Impact
The qla2xxx SCSI driver allocates a diagnostics buffer with kmalloc_obj, which does not zero memory. The driver then copies this buffer back to user space, but only the user‑requested portion is zeroed; the remaining fields retain whatever was on the kernel heap, leading to leakage of uninitialized kernel data. The vulnerability is an information‑exposure flaw that could expose sensitive memory contents to an unprivileged user.
Affected Systems
Any Linux system running a kernel that includes the qla2xxx driver before the safety fix commit. The vulnerability does not target a particular kernel version list, so all affected distributions using the unpatched driver are at risk until the kernel is updated.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to a QLogic SCSI device to trigger the diagnostic operation and read the exposed data. The impact is a confidentiality breach; integrity and availability are not directly affected by the attack vector described. The risk level remains low to moderate depending on the system’s exposure to local users who can issue SCSI commands.
OpenCVE Enrichment