Impact
The flaw occurs when the qla2xxx NVMe driver calls INIT_WORK() on a work_struct that is already queued. Reinitializing a queued work item corrupts the workqueue list, which can cause kernel crashes or infinite worker loops. This results in loss of system availability, as the kernel may panic or misbehave after a repeated abort for the same command.
Affected Systems
The vulnerability affects Linux kernel implementations that use the qla2xxx NVMe driver. All kernel versions shipped with the driver before the patch apply to this issue; the exact versions are not enumerated in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw. The EPSS score is below 1%, so the probability of widespread exploitation is currently low, and it is not listed in the CISA KEV catalog. However, an attacker who can trigger concurrent aborts on a vulnerable system could destabilize the kernel, resulting in denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA