Impact
A null‑pointer dereference in the qla2xxx SCSI driver causes a kernel crash when a privileged user writes malformed data to the debugfs FCE trace file. The bug also inverts the enable/disable logic due to incorrect handling of the return value, potentially misconfiguring FCE tracing. The result is a local denial of service as the kernel Oopses and may reboot or become unreachable until a reboot occurs.
Affected Systems
Linux kernel builds that include the qla2xxx driver and expose the FCE debugfs interface are affected. Any kernel version prior to the upstream patch referenced in the advisory is vulnerable. Specific kernel releases are not enumerated in the advisory, so all kernels with the unpatched qla2xxx code should be treated as susceptible.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of public exploitation. Because the debugfs write operation requires root or equivalent privileges, only a local attacker with sufficient permissions can trigger the fault. The impact is a local kernel crash rather than remote code execution. Consequently, the overall risk is moderate, and applying the upstream fix as soon as possible is strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA