Impact
During a SCSI host teardown, the qla84xx_put_chip() function releases a reference to the cs84xx structure without clearing its pointer. This occurs before scsi_remove_host() removes the sysfs attribute that exposes the fw_version. A concurrent read of that attribute can therefore dereference freed memory, causing a use‑after‑free. If an attacker can trigger the race condition, the resulting kernel memory corruption can lead to arbitrary code execution or a local denial‑of‑service, as the fault occurs in kernel space.
Affected Systems
The vulnerability is present in the Linux kernel for all distributions that ship the qla2xxx SCSI driver, including the qla84xx code. It affects any system that loads the qla2xxx module before the kernel patch is applied. No specific kernel version is listed, so all affected kernels that include the unpatched driver code are at risk.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not in the CISA KEV catalog. The attack requires a local user who can manipulate the SCSI host teardown process and read the sysfs attribute simultaneously, making it a privilege‑escalation or local exploitation vector. While the risk is moderate, it remains important to apply the patch promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA