Executive brief
A vulnerability was identified in the Linux kernel's QLogic Fibre Channel driver, which manages high-speed data storage connections. An error in how the system releases temporary memory during certain storage operations can lead to memory corruption. This could potentially allow an attacker to disrupt system stability or gain unauthorized access to data. Updates have been released to ensure memory is handled correctly.
Technical details
A memory management bug exists in the qla2xxx driver within the qla2xxx_process_purls_iocb() function. The function allocates 'purex' items using qla24xx_alloc_purex_item(), which may return either a dynamically allocated object or a pre-allocated object from a per-adapter pool. The error handling path incorrectly used kfree() to release these items regardless of their origin; calling kfree() on a pool-resident object leads to memory corruption. The fix replaces kfree() with qla24xx_free_purex_item(), which correctly identifies the allocation type. The vulnerability is reachable via unsolicited LS Request/Response support for NVMe over Fibre Channel.
Affected products
- Linux Linux Kernel 6.6 to 6.6.120, 6.12 to 6.12.63, 6.17 to 6.17.13, 6.18 to 6.18.2
Timeline
- 2025-11-13: disclosed: Initial patch submitted by Zilin Guan
- 2025-11-19: patched: Mainline kernel fix committed
- 2025-12-24: advisory: CVE-2025-68741 published
References
- https://git.kernel.org/stable/c/4bccd506a1f1ab01d1f45b2a3effff6bedc73cf9
- https://git.kernel.org/stable/c/5fa1c8226b4532ad7011d295d3ab4ad45df105ae
- https://git.kernel.org/stable/c/78b1a242fe612a755f2158fd206ee6bb577d18ca
- https://git.kernel.org/stable/c/8e9f0a0717ba31d5842721627ade1e62d7aec012
- https://git.kernel.org/stable/c/cfe3e2f768d248fd3d965d561d0768a56dd0b9f8