SB2026030463 - Double free in Linux kernel scsi qla2xxx driver
Published: March 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free (CVE-ID: CVE-2025-71238)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the qla2x00_update_optrom() function in drivers/scsi/qla2xxx/qla_bsg.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/057a5bdc481e58ab853117254867ffb22caf9f6e
- https://git.kernel.org/stable/c/27ac9679c43a09e54e2d9aae9980ada045b428e0
- https://git.kernel.org/stable/c/31f33b856d2324d86bcaef295f4d210477a1c018
- https://git.kernel.org/stable/c/708003e1bc857dd014d4c44278d7d77c26f91b1c
- https://git.kernel.org/stable/c/74e7458537cd9349cf019862e51491f670871707
- https://git.kernel.org/stable/c/871f6236da96c4a9712b8a29d7f555f767a47e95
- https://git.kernel.org/stable/c/c2c68225b1456f4d0d393b5a8778d51bb0d5b1d0
- https://git.kernel.org/stable/c/f2bbb4db0e4a4fbd5e649c0b5d8733f61da24720