Executive brief
A vulnerability in the Linux kernel's QLogic Fibre Channel driver can cause a system crash (kernel panic). This occurs when the system attempts to abort storage commands while running in a specific 'target-mode' configuration. An exploit would result in a complete loss of availability for the affected server or industrial controller.
Technical details
A regression was introduced in the qla2xxx driver's __qla2x00_abort_all_cmds() function where the code attempted to perform lockless command completion. The vulnerable code failed to validate the command type (sp->cmd_type) and incorrectly assumed TYPE_SRB. In target-mode configurations using TYPE_TGT_CMD, this results in a jump to an invalid or NULL pointer, triggering a kernel panic (NULL pointer dereference). The fix involves reverting the problematic lockless logic and ensuring proper spinlock usage and type checking. This is reachable during ISP error recovery or command abort sequences.
Affected products
- Linux Linux Kernel 6.1.133; 6.6; 6.12; 6.13
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-11-10: disclosed: Initial patch submission
- 2026-01-02: patched: Merged into stable branches
- 2026-01-13: advisory: CVE-2025-68818 published
References
- https://git.kernel.org/stable/c/1c728951bc769b795d377852eae1abddad88635d
- https://git.kernel.org/stable/c/50b097d92c99f718831b8b349722bc79f718ba1b
- https://git.kernel.org/stable/c/b04b3733fff7e94566386b962e4795550fbdfd3d
- https://git.kernel.org/stable/c/b10ebbfd59a535c8d22f4ede6e8389622ce98dc0
- https://git.kernel.org/stable/c/b57fbc88715b6d18f379463f48a15b560b087ffe
- https://git.kernel.org/stable/c/c5c37a821bd1708f26a9522b4a6f47b9f7a20003
- https://git.kernel.org/stable/c/e9e601b7df58ba0c667baf30263331df2c02ffe1