Impact
The Linux kernel’s qla2xxx SCSI driver contains a race condition in the report‑ID acquisition path for format‑1. The code drops an essential lock before updating a B‑tree that manages host maps, violating the documented locking contract. Concurrent updates can corrupt the tree, causing kernel panics, crashes, or driver instability. This leads to denial of service at the kernel level.
Affected Systems
All Linux kernel builds that include the vulnerable qla2xxx SCSI driver, particularly those using QLogic QLA2XXX adapters, are affected. The vulnerability is specific to the Linux kernel’s qla2xxx driver code and the associated host map B‑tree structures.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of <1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need local or privileged access to send SCSI commands that trigger the format‑1 path, which can lead to a kernel crash and service denial. The likely attack vector is a local or privileged threat actor leveraging SCSI commands to induce the race condition, potentially causing a denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA