Impact
In the Linux kernel's qla2xxx SCSI driver, the code releases the response‑queue MSI‑X interrupt after the request queue has already been freed. While the legacy request queue is available, a response interrupt can still arrive, causing the driver’s work function to run and dereference freed memory. These dereferences access objects that no longer exist, triggering a use‑after‑free that can corrupt the kernel or cause a system crash. The flaw is a classic memory corruption vulnerability that can lead to denial‑of‑service if exploited.
Affected Systems
Any Linux kernel that includes the unpatched qla2xxx driver is vulnerable. The advisory references several upstream commits that address the issue, so any distribution whose kernel has not yet incorporated those commits will remain at risk. The vulnerability applies to all Linux distributions that ship this driver for QLogic SCSI adapters, regardless of version, until the fixes are integrated.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates that exploitation is currently uncommon. The issue is not listed in CISA’s KEV catalog. Exploitation requires local or privileged access to the QLogic host bus adapter; an attacker who can inject SCSI commands or control the initiator side of the fabric can trigger the race window and cause a kernel crash or denial of service. Since the flaw depends on timing between interrupt handling and memory free, it is generally considered a local escalation vector.
OpenCVE Enrichment
Debian DLA
Debian DSA