Impact
The vulnerability arises when the QLogic qla2xxx SCSI driver copies uninitialized stack data into user‑visible sysfs files. This uninitialized mailbox structure is returned when certain error conditions occur, allowing a local user to read kernel stack contents through the fw_state and mpi_fw_state sysfs entries. The flaw is a classic Uninitialized Local Variable vulnerability (CWE‑457), resulting in information disclosure of potentially sensitive kernel data.
Affected Systems
The flaw affects the Linux kernel’s qla2xxx SCSI driver, which is part of the standard kernel tree. No specific kernel version ranges are listed in the advisory, so any kernel that includes the unpatched qla2xxx driver code may be affected. Operating systems that ship with this driver unchanged are at risk.
Risk and Exploitability
The CVSS score is not supplied, but the EPSS score is <1%, indicating that exploitation is considered unlikely at present. Because the leak occurs via sysfs, the attack requires local user access and only reads kernel memory; elevated privileges are not needed. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been identified, so the overall risk is low to moderate for a local user but could be significant if an attacker can gain local access.
OpenCVE Enrichment
Debian DLA
Debian DSA