Impact
The qla2xxx SCSI driver computes the number of request and response queues from the advertised MSI‑X vector count. Because the vector count is stored in a 16‑bit field while the derived queue counts are held in 8‑bit variables, a device announcing more than 256 vectors causes the calculated queue count to be truncated. When the truncation yields zero, the driver allocates a zero‑size queue object, which returns a non‑NULL ZERO_SIZE_PTR. The subsequent assignment to the queue map dereferences this pointer, corrupting kernel memory or causing a kernel panic. This flaw is an integer truncation leading to an invalid pointer dereference and can result in kernel‑level memory corruption or denial of service.
Affected Systems
All Linux kernel releases that bundle the qla2xxx SCSI driver are potentially impacted because the vulnerability is located entirely within the kernel source. No specific vendor, product or version list was supplied, so any distribution shipping a kernel that contains the unpatched qla2xxx driver may be at risk until the fix is applied.
Risk and Exploitability
The CVSS score of 8.4 denotes a high‑severity flaw with local to privileged impact. The EPSS score of <1 % indicates that, as of the latest data, exploitation attempts are unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker would need the ability to introduce a misconfigured or malicious SCSI controller that advertises an anomalous MSI‑X vector count—typically via physical access or trusted hot‑plug. Once triggered, the kernel memory corruption or crash could enable privilege escalation or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA