Impact
The vulnerability resides in the qla2xxx SCSI driver of the Linux kernel. When the driver receives a status completion for a command that has already been returned or aborted by the firmware, it calls qla_chk_edif_rx_sa_delete_pending(). This routine obtains the SCSI command pointer via GET_CMD_SP(sp) and immediately accesses cmd->sc_data_direction. If cmd is NULL, the kernel dereferences a null pointer in interrupt context, causing a crash. The crash results in a kernel panic and a service disruption.
Affected Systems
Affected systems are Linux kernel implementations that include the qla2xxx SCSI driver before the patch commit found at git.kernel.org stable. The affected vendor is the Linux project and the product is the Linux kernel. The specific versions are not enumerated in the advisory, so all kernel releases containing the unpatched qla2xxx driver are at risk until the fix is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is below 1%, suggesting a low probability of exploitation, and the issue is not listed in the CISA KEV catalog. However, an attacker with the ability to control the SCSI firmware or induce the erroneous status completion can trigger a NULL pointer dereference and force a kernel panic, leading to a denial‑of‑service event. The likely attack vector is local via compromised firmware or a privileged user with direct SCSI command access.
OpenCVE Enrichment
Debian DLA
Debian DSA