Executive brief
A vulnerability in the Linux kernel's QLogic qla4xxx SCSI driver could allow a local user to cause a system crash. The issue occurs when the driver incorrectly handles error messages during connection attempts, leading to a kernel 'Oops' or failure. This primarily impacts system availability and could disrupt operations on servers using affected QLogic storage hardware.
Technical details
A vulnerability exists in the qla4xxx SCSI driver within the Linux kernel due to improper error handling in the qla4xxx_get_ep_fwdb() function. While this function is designed to return NULL on failure, it incorrectly propagates error pointers returned by qla4xxx_ep_connect(). When these error pointers are subsequently dereferenced by the caller, it triggers a kernel Oops. This is classified as a NULL pointer dereference (CWE-476). An attacker with local access could potentially trigger this condition to cause a Denial of Service (DoS). Patches have been released across multiple stable kernel branches to ensure error pointers are converted to NULL before propagation.
Affected products
- Linux Linux Kernel versions from 3.2.1 up to 5.4.297; 5.5 up to 5.10.241; 5.11 up to 5.15.190; 5.16 up to 6.1.149; 6.2 up to 6.6.103; 6.7 up to 6.12.44; 6.13 up to 6.16.4
Timeline
- 2025-08-13: patched: Initial patch authored by Dan Carpenter
- 2025-09-05: disclosed: CVE published by kernel.org
- 2025-09-05: advisory: NVD record created
References
- https://git.kernel.org/stable/c/325bf7d57c4e2a341e381c5805e454fb69dd78c3
- https://git.kernel.org/stable/c/46288d12d1c30d08fbeffd05abc079f57a43a2d4
- https://git.kernel.org/stable/c/9dcf111dd3e7ed5fce82bb108e3a3fc001c07225
- https://git.kernel.org/stable/c/ad8a9d38d30c691a77c456e72b78f7932d4f234d
- https://git.kernel.org/stable/c/d0225f41ee70611ca88ccb22c8542ecdfa7faea8
- https://git.kernel.org/stable/c/f1424c830d6ce840341aac33fe99c8ac45447ac1
- https://git.kernel.org/stable/c/f4bc3cdfe95115191e24592bbfc15f1d4a705a75