Executive brief
The Linux kernel's SCSI qedi driver (used to manage iSCSI block storage connections on enterprise servers) has a race condition in its driver removal code. When the driver is unloaded, scheduled recovery work can attempt to access kernel memory structures after they have been freed, potentially causing a system crash or allowing code execution.
Technical details
A use-after-free vulnerability exists in qedi_remove() where the driver frees the SCSI host structure via iscsi_host_free() and scsi_host_put() before cancelling scheduled work queues. If qedi_recovery_handler() or qedi_board_disable_work() are executing on another CPU core, they will call iscsi_host_for_each_session() on the freed qedi->shost pointer, causing a use-after-free condition. The fix adds cancel_delayed_work_sync() calls for both recovery_work and board_disable_work before the cleanup sequence in __qedi_remove(). This is a kernel-mode driver vulnerability requiring the ability to trigger driver removal, typically local or with system administration privileges.
Affected products
- Linux Linux Kernel Versions with qedi driver from introduction through fixed versions (approximately 4.14+)
Timeline
- 2025-12-24: disclosed
- 2023-05-17: patched: Fix merged to stable kernel trees