Impact
The qla2xxx driver’s helper function allocates and advances an NVMe submission ring while assuming a hardware lock is held, but the function itself takes no lock. Two callers invoke it without acquiring the required producer lock, allowing simultaneous ring access during normal I/O submission. This race condition can corrupt the ring’s producer state, resulting in duplicated or dropped NVMe commands. The flaw is a classic lock‑mismanagement scenario, classified as CWE‑362.
Affected Systems
All Linux kernel installations that provide the qla2xxx SCSI driver, regardless of distribution. The vulnerability is present in kernel versions prior to the application of the patch referenced in the provided kernel commits.
Risk and Exploitability
The CVSS score of 9.8 marks this as critical, while the EPSS score of less than 1 percent indicates a low probability of real‑world exploitation. The bug operates in user‑level process context and requires a driver user with the ability to influence NVMe operations or a local attacker with kernel privileges. It is listed in no CISA KEV catalog and does not affect remote attacker vectors described in the CVE description. When exploited, it threatens the integrity and availability of storage traffic by potentially corrupting command streams.
OpenCVE Enrichment
Debian DLA
Debian DSA