Impact
In the Linux kernel SCSI driver for QLogic QLA2xxx hosts a flaw in the timeout handling of async IOCBs. The timeout logic unconditionally invokes the completion callback without verifying that the command buffer has been removed from the list of outstanding commands. If the interrupt service routine finishes the command first, the first completion frees the callback structure on the stack. When the timeout handler later calls the same completion function it writes to the already freed stack space, creating a use‑after‑free condition. In kernel contexts a use‑after‑free can be leveraged to execute arbitrary code or elevate privileges to root. The CVSS score of 9.8 reflects the potential for remote privilege escalation once an attacker can trigger the double completion.
Affected Systems
The vulnerability resides in the qla2xxx driver, part of the Linux kernel. It affects any system running a kernel version prior to the patch commit referenced in the advisory. All Linux distributions that ship the affected QLogic SCSI driver are included, regardless of vendor. Specific version ranges are not listed in the advisory, but the kernel code was updated in recent stable releases.
Risk and Exploitability
Based on the description, it is inferred that the attacker must have the ability to send SCSI commands to a QLogic QLA2xxx adapter, which typically requires local privileged access or remote exploitation of a service that interacts with the SCSI subsystem. The EPSS score of less than 1% indicates that the flaw is considered unlikely to be exploited in the wild at present, yet the high CVSS score and lack of KEV listing do not diminish the danger to systems that remain unpatched. Once a command can be timed out, the double‑completion can be triggered to achieve a use‑after‑free and potentially gain kernel execution.
OpenCVE Enrichment
Debian DLA
Debian DSA