Impact
During firmware parsing for the qlcnic network driver, size and offset values are not fully validated. The code performs unchecked additions and multiplications when reading table entries and then dereferences pointers at firmware-controlled offsets. Malformed values can wrap, causing a comparison with the firmware size to be bypassed and allowing the loader to read beyond the allocated buffer. This out-of-bounds read may leak kernel memory contents and, with additional manipulation, potentially enable arbitrary code execution in kernel mode.
Affected Systems
All Linux kernel releases that ship the qlcnic driver are affected. Since the vendor/product list is generic (Linux:Linux) and the CPE identifies the Linux kernel itself, any kernel containing the unpatched qlcnic module could be vulnerable. No specific kernel versions are enumerated, so the scope remains broad.
Risk and Exploitability
EPSS below 1% and not listed in CISA KEV indicates a low current exploitation probability. The flaw requires an attacker to supply a crafted firmware image to the qlcnic driver, which typically necessitates local or privileged access to the network device’s firmware interface. If such access is available, the attacker can trigger an out-of-bounds read that may lead to kernel memory corruption or arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA