Impact
The kernel’s qla2xxx SCSI driver allocates a 256‑byte DMA bounce buffer using dma_pool_alloc(), which does not clear the memory. The driver only writes the first few bytes before passing the buffer to qla2x00_write_sfp(), where a user‑controlled length field can be overridden to read up to 255 bytes from the buffer. Because the remaining bytes are uninitialised, the device performs a DMA read of the full length, causing stale memory contents to be written to the device’s flash storage. This flaw can corrupt firmware or other persistent data on the device, potentially leading to loss of integrity and application failure. The weakness involves improper initialization and a form of heap‑based buffer misuse, corresponding to CWE‑122 and CWE‑665.
Affected Systems
Any Linux kernel that includes the qla2xxx driver before the patch that replaces dma_pool_alloc() with dma_pool_zalloc() in the FRU/I2C bsg handlers is affected. The specific kernel releases are not listed in the advisory, so all builds using the vulnerable code path are considered at risk.
Risk and Exploitability
Because the exploit requires the attacker to supply a specially crafted SFP payload that is transmitted to the device, the attack vector is local to the environment that controls the SCSI I/O. The EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the impact on device integrity is high, as corrupted flash may render the device unusable. The CVSS score is not provided, but the vulnerability’s potential to permanently alter stored data suggests a high severity if an attacker succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA