Junglewise Threat Intelligence

CVE-2023-54100: Linux kernel SCSI qedi use-after-free in driver removal

CVE-2023-54100 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCSI qedi driver (used to manage iSCSI block storage connections on enterprise servers) has a race condition in its driver removal code. When the driver is unloaded, scheduled recovery work can attempt to access kernel memory structures after they have been freed, potentially causing a system crash or allowing code execution.

Technical details

A use-after-free vulnerability exists in qedi_remove() where the driver frees the SCSI host structure via iscsi_host_free() and scsi_host_put() before cancelling scheduled work queues. If qedi_recovery_handler() or qedi_board_disable_work() are executing on another CPU core, they will call iscsi_host_for_each_session() on the freed qedi->shost pointer, causing a use-after-free condition. The fix adds cancel_delayed_work_sync() calls for both recovery_work and board_disable_work before the cleanup sequence in __qedi_remove(). This is a kernel-mode driver vulnerability requiring the ability to trigger driver removal, typically local or with system administration privileges.

Affected products

  • Linux Linux Kernel Versions with qedi driver from introduction through fixed versions (approximately 4.14+)

Timeline

  • 2025-12-24: disclosed
  • 2023-05-17: patched: Fix merged to stable kernel trees

References

Related threats