Impact
The qla2xxx SCSI driver in the Linux kernel contains a logic flaw that causes it to send a second mailbox command to a Q Logic adapter when the chip is down or EEH busy. This command is issued outside the optrom_mutex lock and can trigger a hang during ISP reset or PCI error recovery, effectively rendering the device unusable. The bug turns an otherwise harmless mailbox failure into a second unsynchronised attempt, resulting in a denial‑of‑service condition for any host using the affected adapter.
Affected Systems
The flaw exists in the kernel’s qla2xxx driver code that is part of all Linux kernels using the unpatched driver. Consequently any Linux installation with a Q Logic SCSI adapter connected is affected until the driver is updated to the patch that removes the second command and restricts mailbox issuance to a valid chip state. No specific version range is supplied, so the vulnerability applies to all kernels that include the buggy code.
Risk and Exploitability
The EPSS score indicates a probability of exploitation below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting low attacker interest. The flaw would require local privilege or kernel‑level execution to trigger the erroneous mailbox request; therefore the exploit path is limited, though an attacker who succeeds could force a complete adapter hang, causing a denial of service for the host. Overall risk is low, but for environments that rely on uninterrupted SCSI storage this defect can be critical.
OpenCVE Enrichment
Debian DLA
Debian DSA