Executive brief
A vulnerability was identified in the Linux kernel's BFA SCSI driver, which manages certain storage hardware connections. If the driver fails to initialize properly, it can leave the system in an unstable state that may lead to a system crash or allow an attacker to gain elevated privileges. This issue occurs during specific hardware probing or driver uninstallation sequences.
Technical details
A double-free vulnerability exists in the Linux kernel SCSI BFA driver (drivers/scsi/bfa/bfad_im.c). When the bfad_im_probe() function encounters a failure during initialization, it frees the memory allocated for the 'im' structure but fails to nullify the bfad->im pointer. If the driver is subsequently uninstalled, the state machine enters the bfad_sm_stopping state and invokes bfad_im_probe_undo(), which attempts to free the same pointer a second time. This flaw can be triggered by a local user and may lead to memory corruption, a kernel panic (DoS), or potentially local privilege escalation. The issue has been resolved by ensuring the pointer is set to NULL immediately after the initial free in the error path.
Affected products
- Linux Linux Kernel versions from 2.6.33 up to 5.4.297; 5.5 up to 5.10.241; 5.11 up to 5.15.190; 5.16 up to 6.1.149; 6.2 up to 6.6.103; 6.7 up to 6.12.43; 6.13 up to 6.15.11; 6.16 up to 6.16.2
Timeline
- 2025-09-04: advisory: Initial publication of the vulnerability details.
- 2025-08-20: patched: Fix committed to various stable kernel branches.
References
- https://git.kernel.org/stable/c/13f613228cf3c96a038424cd97aa4d6aadc66294
- https://git.kernel.org/stable/c/39cfe2c83146aad956318f866d0ee471b7a61fa5
- https://git.kernel.org/stable/c/50d9bd48321038bd6e15af5a454bbcd180cf6f80
- https://git.kernel.org/stable/c/684c92bb08a25ed3c0356bc7eb532ed5b19588dd
- https://git.kernel.org/stable/c/8456f862cb95bcc3a831e1ba87c0c17068be0f3f
- https://git.kernel.org/stable/c/8e03dd9fadf76db5b9799583074a1a2a54f787f1
- https://git.kernel.org/stable/c/9337c2affbaebe00b75fdf84ea0e2fcf93c140af