Impact
The flaw is in the Linux kernel qla2xxx SCSI driver; the function qla2x00_update_fru_versions() copies a user‑supplied BSG request into a fixed 256‑byte stack buffer without validating the count field. The count is taken directly from the user’s request, and the code then iterates that many times over the embedded qla_image_version array. Only six entries fit in the buffer; a larger count causes the pointer to read beyond the buffer’s bounds, leaking adjacent kernel stack memory to the device via qla2x00_write_sfp(). This out‑of‑bounds read can expose sensitive kernel data.
Affected Systems
Any Linux system that contains the unpatched qla2xxx driver is affected, regardless of architecture. The vulnerability exists in all kernel releases that include the legacy qla2xxx routine; the fix was introduced in later revisions with the boundary check and request rejection logic.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low exploitation probability. Exploitation requires constructing a BSG request with an invalid count and sending it to the qla2xxx device file, which typically needs local or privileged access to that hardware interface. Successful exploitation results in memory disclosure from the kernel stack, which could assist in further privilege escalation or information gathering.
OpenCVE Enrichment
Debian DLA
Debian DSA