Impact
During a sysfs reset operation the qla2xxx driver calls the get_flash_version() function without holding the optrom_mutex. The same mutex is used in the VPD update path during flash operations. When these two paths run concurrently, their flash register accesses can interleave, producing corrupted read data. The flaw is a classic data race that leads to inconsistent flash version readings.
Affected Systems
Any Linux kernel distribution that includes the qla2xxx SCSI driver is potentially affected, provided the kernel has not been updated with the patch that serializes the flash version read. No specific version numbers are disclosed, but the fix is available in recent kernel commits as referenced.
Risk and Exploitability
The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. No CVSS score is reported. The attack vector requires simultaneous access to the reset sysfs entry and a VPD or optrom flash operation, which limits remote exploitation possibilities. Overall, the risk of successful exploitation is low given the narrow surface and lack of public exploits.
OpenCVE Enrichment
Debian DLA
Debian DSA