Impact
The vulnerability resides in the Linux kernel’s qla2xxx SCSI target driver. When handling status IOCBs, the code path assumes all commands are of type SRB_SCSI_CMD and accesses the command pointer through a union overlay. If firmware delivers an unexpected STATUS_TYPE IOCB for a non‑SCSI handle, the union can expose garbage as a non‑NULL pointer, bypassing null checks and ultimately dereferencing an invalid pointer. This results in a wild pointer dereference that can crash the kernel or corrupt memory, thereby denying service or potentially allowing privilege escalation if the crash can be repeatedly triggered.
Affected Systems
All Linux kernel distributions that ship the unpatched qla2xxx driver are affected. The flaw is present in the generic Linux kernel code, so any system using the qla2xxx adapter without the patch is vulnerable. Since the vendor list shows Linux:Linux twice, the issue applies across all Linux kernel versions before the fix.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits exist. The likely attack vector involves local or device‑privileged access to a controller that can inject a malformed status IOCB; attackers would need to bypass normal firmware validation to trigger the pointer dereference.
OpenCVE Enrichment
Debian DLA
Debian DSA