SB20251226327 - Resource management error in Linux kernel scsi qla2xxx driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-54108)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the qla_nvme_release_fcp_cmd_kref(), qla_nvme_release_ls_cmd_kref() and qla_nvme_ls_req() functions in drivers/scsi/qla2xxx/qla_nvme.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3a564de3a299856f2cbd289649cea2e20d671a43
- https://git.kernel.org/stable/c/3ee4f1991c54c6707aa9df47e51c02ea25bb63e3
- https://git.kernel.org/stable/c/77302fb0e357da666d5249a6e91078feeef3dade
- https://git.kernel.org/stable/c/ad6af23593594402c826eefdf43ae174e5f0f202
- https://git.kernel.org/stable/c/c75e6aef5039830cce5d4cf764dd204522f89e6b
- https://git.kernel.org/stable/c/e596253113b69b4018818260bd5da40c201bee73
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.173