Impact
In the Linux kernel the qla2xxx SCSI driver exposes an unchecked i2c->length field in its BSG handlers. The driver copies or DMA‑transfers the specified length without bounding it against the fixed 64‑byte buffer. When the length exceeds the buffer, the write path over‑reads the stack and overwrites heap memory, and the read path overflows the stack buffer and later copies the overrun data to the kernel. An attacker with CAP_SYS_RAWIO can trigger these overflows to corrupt kernel data structures, enabling an elevation of privilege or remote code execution.
Affected Systems
All Linux kernel builds prior to the commit that introduced the bounds‑check are affected. The vulnerability exists in the qla2xxx SCSI driver regardless of platform, so any system running an unpatched kernel that includes this driver is at risk. No specific vendor version enumeration is supplied, but the patch is linked in the provided references and applies to all kernels before the fix.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the flaw requires CAP_SYS_RAWIO, so only processes or users with raw I/O capability can exercise it. Because a kernel memory corruption can have catastrophic consequences, the overall severity is high for environments that grant raw I/O access, while systems that enforce strict capability restrictions face a lower risk.
OpenCVE Enrichment
Debian DLA
Debian DSA