Impact
The vulnerability is a use-after-free race condition in the qla2xxx SCSI driver of the Linux kernel. When the firmware-dump consumers copy data from the FCE trace buffer while the buffer may have been freed by another path, the driver accesses memory that has already been freed. This can corrupt kernel memory or trigger a kernel panic, causing a system crash. The flaw arises from holding a mutex that protects the buffer while freeing it, but other code paths that read the buffer use a different lock and have no guard against the free.
Affected Systems
All Linux kernels that contain the qla2xxx SCSI driver in its pre‑patch state are affected. No specific release numbers are listed in the advisory; therefore, any kernel versions that have the older implementation of qla2xxx and expose the debugfs FCE trace interface are impacted. The list of affected vendors is not provided; the driver is distributed as part of the mainline Linux kernel.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA KEV, indicating a low statistical likelihood of exploitation in recent observations. The likely attack vector inferred from the description is local access to the debugfs interface to trigger a firmware dump, which would require the attacker to have privileged access to the system. No public exploits are mentioned in the supplied data. Even with the low probability of exploitation, the high potential impact of a kernel crash or memory corruption warrants timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA