Impact
The qla2xxx SCSI driver in the Linux kernel contains a race condition where a redundant flash read is performed after releasing the optrom mutex. Because the second read occurs without the lock, concurrent optrom operations can access the flash simultaneously, which may corrupt firmware data or leak its contents, undermining both integrity and confidentiality of the device. This flaw is tied to improper synchronization and can allow a compromised system or device to read or modify flash data in an uncontrolled fashion.
Affected Systems
All Linux kernel releases that include the qla2xxx driver before the patch, regardless of distribution, are affected. The vulnerability is tied to the Linux kernel’s SCSI subsystem and therefore applies to any system that loads the qla2xxx driver via the kernel.
Risk and Exploitability
The EPSS score is less than 1 %, and the flaw is not listed in the CISA KEV catalog, indicating that no active exploit is widely known. The likely attack vector is local, requiring either physical access to the device or privileged execution that can trigger concurrent optrom operations. While exploitation could lead to firmware corruption, the ease of attack and overall risk remain moderate in the absence of an identified exploit. The primary concern, however, is the potential for integrity compromise of the flash memory used by the driver.
OpenCVE Enrichment
Debian DLA
Debian DSA