Impact
The qla2xxx SCSI driver contains a race condition that allows a virtual port (vport) to be freed while still in use. During an ID acquisition the driver releases a lock before taking a reference on the vport, creating a window where a concurrent deallocation can remove the port and release its memory, leading to a use‑after‑free in kernel space and potential memory corruption. This flaw is represented by CWE-416 and can compromise kernel image integrity if exploited.
Affected Systems
All Linux system images that include the default qla2xxx SCSI driver are affected. The CVE description does not list specific kernel releases or distribution names; therefore any distribution that ships the driver unmodified, across current and past kernel versions, may be vulnerable. No version constraints are supplied by the CNA, so the impact may span all kernel releases that contain the old qla2xxx code.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the EPSS score of <1% suggests that the probability of exploitation is very low according to current metrics. The CISA KEV catalog does not list this vulnerability. The likely attack vector is inferred: a malicious or compromised entity that can issue SCSI commands through the qla2xxx driver—such as a local attacker with privileged access to the host bus adapter or a remote attacker able to interact with the SCSI layer—could trigger the race condition. More information about the exact attack surface is not present in the CVE data and must be determined through further analysis.
OpenCVE Enrichment
Debian DLA
Debian DSA