Impact
The vulnerability arises in the qla2xxx SCSI driver when the length field of a target response (rsp_info_len) is taken directly from the target’s FPI response data. If a target supplies a length larger than the allotted sense buffer (par_sense_len), the unsigned subtraction underflows and the driver advances the sense_data pointer beyond the bounds of the IOCB data area. The subsequent memcpy copies up to the maximum sense buffer size, leaking adjacent kernel or heap memory into the command’s sense buffer. This results in a confidentiality compromise rather than a denial‑of‑service or code execution flaw.
Affected Systems
The flaw affects Linux kernel implementations that include the qla2xxx driver. No specific kernel release numbers are listed, so all current distributions deploying the driver are potentially vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 9.1 classifies this as critical, yet the EPSS score of less than 1% indicates a low probability of active exploitation at this time. The vulnerability is not yet in CISA’s KEV catalog. The likely attack vector is a malicious or misbehaving SCSI target, such as a QLogic QLA2xxx adapter, exploiting the driver from within the host’s SCSI subsystem.
OpenCVE Enrichment
Debian DLA
Debian DSA