Executive brief
A vulnerability in the Linux kernel's Emulex LightPulse Fibre Channel (lpfc) driver could allow a local user to cause a system crash. The issue occurs during specific hardware initialization failures, where the system attempts to clean up resources that haven't been fully set up yet. This results in a 'null pointer dereference,' leading to a kernel panic and loss of system availability.
Technical details
A NULL pointer dereference exists in the lpfc driver within the SCSI subsystem of the Linux kernel. The vulnerability occurs in the lpfc_sli4_vport_delete_fcp_xri_aborted() function. If lpfc_sli4_read_rev() fails during HBA setup, the cleanup routine is triggered before the sli4_hba.hdwqs hardware queues are allocated. When the routine attempts to acquire the abts_io_buf_list_lock for the first hardware queue, it dereferences a NULL pointer. This is a local attack vector requiring low privileges, resulting in a kernel panic (DoS). Patches have been merged into various stable kernel branches.
Affected products
- Linux Linux Kernel 5.1 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-06-18: other: Patch submitted by developer
- 2025-09-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/46a0602c24d7d425dd8e00c749cd64a934aac7ec
- https://git.kernel.org/stable/c/571617f171f723b05f02d154a2e549a17eab4935
- https://git.kernel.org/stable/c/5e25ee1ecec91c61a8acf938ad338399cad464de
- https://git.kernel.org/stable/c/6698796282e828733cde3329c887b4ae9e5545e9
- https://git.kernel.org/stable/c/6711ce7e9de4eb1a541ef30638df1294ea4267f8
- https://git.kernel.org/stable/c/74bdf54a847dab209d2a8f65852f59b7fa156175
- https://git.kernel.org/stable/c/7925dd68807cc8fd755b04ca99e7e6f1c04392e8