VDB

CISA-2023-53322

CISA-2023-53322 PUBLISHED CVSS 7.8 HIGH

Reported by Linux · Published September 16, 2025

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rport System crash due to use after free. Current code allows terminate_rport_io to exit before making sure all IOs has returned. For FCP-2 device, IO's can hang on in HW because driver has not tear down the session in FW at first sign of cable pull. When dev_loss_tmo timer pops, terminate_rport_io is called and upper layer is about to free various resources. Terminate_rport_io trigger qla to do the final cleanup, but the cleanup might not be fast enough where it leave qla still holding on to the same resource. Wait for IO's to return to upper layer before resources are freed.

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
LinuxLinux715848ca6fffeb6362a50887d9c26245bd5dfba9, 715848ca6fffeb6362a50887d9c26245bd5dfba9, 715848ca6fffeb6362a50887d9c26245bd5dfba9
LinuxLinux2.6.34, 0, 4.14.322
LinuxLinux*, 715848ca6fffeb6362a50887d9c26245bd5dfba9, 715848ca6fffeb6362a50887d9c26245bd5dfba9
linuxlinux_kernel2.6.34, 2.6.34, 2.6.34

Timeline

  • Sep 16, 2025 CVE Published
  • Jan 14, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›