Junglewise Threat Intelligence

CVE-2025-39676: Linux Kernel qla4xxx NULL pointer dereference in SCSI driver

CVE-2025-39676 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's QLogic qla4xxx SCSI driver could allow a local user to cause a system crash. The issue occurs when the driver incorrectly handles error messages during connection attempts, leading to a kernel 'Oops' or failure. This primarily impacts system availability and could disrupt operations on servers using affected QLogic storage hardware.

Technical details

A vulnerability exists in the qla4xxx SCSI driver within the Linux kernel due to improper error handling in the qla4xxx_get_ep_fwdb() function. While this function is designed to return NULL on failure, it incorrectly propagates error pointers returned by qla4xxx_ep_connect(). When these error pointers are subsequently dereferenced by the caller, it triggers a kernel Oops. This is classified as a NULL pointer dereference (CWE-476). An attacker with local access could potentially trigger this condition to cause a Denial of Service (DoS). Patches have been released across multiple stable kernel branches to ensure error pointers are converted to NULL before propagation.

Affected products

  • Linux Linux Kernel versions from 3.2.1 up to 5.4.297; 5.5 up to 5.10.241; 5.11 up to 5.15.190; 5.16 up to 6.1.149; 6.2 up to 6.6.103; 6.7 up to 6.12.44; 6.13 up to 6.16.4

Timeline

  • 2025-08-13: patched: Initial patch authored by Dan Carpenter
  • 2025-09-05: disclosed: CVE published by kernel.org
  • 2025-09-05: advisory: NVD record created

References

Related threats