Impact
The qla2xxx SCSI driver in the Linux kernel allocates 256‑byte buffers on the stack for several bsg handlers. The driver copies only the user‑supplied request payload into this buffer, leaving any remaining bytes uninitialized. When the driver later copies the full buffer back to the reply payload, the stale memory contents become visible to user space. This allows an attacker to read kernel memory that was never intended to be exposed, resulting in an information‑leak vulnerability.
Affected Systems
All Linux kernel releases that include the qla2xxx SCSI driver before the commit that zero‑inits the stack buffer are affected. The vulnerability applies to the Linux kernel product, regardless of vendor, as long as the uninitialized stack buffer is present in the bsg handlers.
Risk and Exploitability
The flaw can be triggered from user space by interacting with the affected SCSI device; the attacker does not need elevated privileges beyond access to the device. The EPSS score indicates a very low probability of exploitation in the near term, and the vulnerability is not currently listed in CISA's KEV catalog. Nevertheless, any untrusted user who can issue SCSI requests to the device can leak portions of kernel memory, potentially exposing sensitive data.
OpenCVE Enrichment
Debian DLA
Debian DSA