Impact
The qla2xxx SCSI driver in the Linux kernel contains a flaw that causes a Block Store Generic (BSG) job to be leaked when a flash image validation fails. The validate_flash_image routine unconditionally reports success, preventing bsg_job_done from being invoked on the error path. This leaves BSG requests dangling until they time out, gradually exhausting block‑layer resources and potentially disrupting legitimate storage operations.
Affected Systems
All Linux kernel installations that include the qla2xxx driver without the later commit that restores bsg_job_done are affected. No specific kernel releases are enumerated, so any kernel build predating the patch is considered vulnerable, regardless of the vendor or distribution.
Risk and Exploitability
The CVSS score of 5.5 and an EPSS score of less than 1 % indicate a moderate severity but a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require interaction with the SCSI transport layer on a system that has a qla2xxx device, suggesting a local or privileged attack vector. While an attacker could trigger repeated leaks to deplete kernel resources, the practical difficulty of continuously invoking the error path keeps overall risk modest.
OpenCVE Enrichment