LiveActive security incident?Get immediate response
CVE Record

CVE-2025-71238: scsi: qla2xxx: Fix bsg_done() causing double free

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free Kernel panic observed on system, [5353358.825191] BUG: unable to handle page fault for address: ff5f5e897b024000 [5353358.825194] #PF: supervisor write access in kernel mode [5353358.825195] #PF: error_code(0x0002) - not-present page [5353358.825196] PGD 100006067 P4D 0 [5353358.825198] Oops: 0002 [#1] PREEMPT SMP NOPTI [5353358.825200] CPU: 5 PID: 2132085 Comm: qlafwupdate.sub Kdump: loaded Tainted: G W L ------- --- 5.14.0-503.34.1.el9_5.x86_64 #1 [5353358.825203] Hardware name: HPE ProLiant DL360 Gen11/ProLiant DL360 Gen11, BIOS 2.44 01/17/2025 [5353358.825204] RIP: 0010:memcpy_erms+0x6/0x10 [5353358.825211] RSP: 0018:ff591da8f4f6b710 EFLAGS: 00010246 [5353358.825212] RAX: ff5f5e897b024000 RBX: 0000000000007090 RCX: 0000000000001000 [5353358.825213] RDX: 0000000000001000 RSI: ff591da8f4fed090 RDI: ff5f5e897b024000 [5353358.825214] RBP: 0000000000010000 R08: ff5f5e897b024000 R09: 0000000000000000 [5353358.825215] R10: ff46cf8c40517000 R11: 0000000000000001 R12: 0000000000008090 [5353358.825216] R13: ff591da8f4f6b720 R14: 0000000000001000 R15: 0000000000000000 [5353358.825218] FS: 00007f1e88d47740(0000) GS:ff46cf935f940000(0000) knlGS:0000000000000000 [5353358.825219] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [5353358.825220] CR2: ff5f5e897b024000 CR3: 0000000231532004 CR4: 0000000000771ef0 [5353358.825221] PKRU: 55555554 [5353358.825222] Call Trace: [5353358.825223] <TASK> [5353358.825224] ? show_trace_log_lvl+0x1c4/0x2df [5353358.825229] ? show_trace_log_lvl+0x1c4/0x2df [5353358.825232] ? sg_copy_buffer+0xc8/0x110 [5353358.825236] ? __die_body.cold+0x8/0xd [5353358.825238] ? page_fault_oops+0x134/0x170 [5353358.825242] ? kernelmode_fixup_or_oops+0x84/0x110 [5353358.825244] ? exc_page_fault+0xa8/0x150 [5353358.825247] ? asm_exc_page_fault+0x22/0x30 [5353358.825252] ? memcpy_erms+0x6/0x10 [5353358.825253] sg_copy_buffer+0xc8/0x110 [5353358.825259] qla2x00_process_vendor_specific+0x652/0x1320 [qla2xxx] [5353358.825317] qla24xx_bsg_request+0x1b2/0x2d0 [qla2xxx] Most routines in qla_bsg.c call bsg_done() only for success cases. However a few invoke it for failure case as well leading to a double free. Validate before calling bsg_done().

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2025-71238 is a Linux kernel bug in the qla2xxx SCSI driver. Some error paths can call cleanup twice, causing a double free and observed kernel panic. Business risk is mainly service disruption on affected Linux systems using this driver, especially storage-connected servers.

Executive priority

Treat as a focused availability risk for Linux storage infrastructure, not a broad internet-facing emergency based on current evidence. Patch affected systems through normal kernel update channels, prioritizing critical servers where an unexpected kernel panic would cause business interruption.

Technical view

The vulnerable qla_bsg.c logic calls bsg_done() in failure cases where most routines only call it on success. That can double free BSG request state and trigger a kernel crash during qla2xxx vendor-specific processing. Stable kernel commits add validation before calling bsg_done().

Likely exposure

Exposure appears limited to Linux systems running affected kernel builds with the qla2xxx driver and BSG vendor-specific paths. The provided trace shows a crash during qlafwupdate.sub on an HPE ProLiant system, but the CVE record does not define hardware scope beyond Linux.

Exploitation context

The source bundle marks KEV as false and provides no evidence of active exploitation. The documented failure mode is a kernel panic from double-free behavior, not a described remote compromise. Public exploit status is not established by the provided sources.

Researcher notes

Evidence supports a double-free in qla2xxx BSG completion handling with stable commits available. Missing data includes CVSS, CWE, precise distribution package ranges, and exploitability analysis. Do not assume remote reachability or privilege impact beyond the documented kernel panic without additional vendor analysis.

Mitigation direction

  • Identify Linux systems using the qla2xxx driver.
  • Prioritize storage hosts where kernel panic would disrupt operations.
  • Apply vendor or distribution kernel updates containing the referenced stable fixes.
  • Check Linux distribution advisories for supported package names and backport status.
  • Avoid unsourced workarounds; follow kernel or distribution guidance.

Validation and detection

  • Confirm current kernel version and distribution patch level.
  • Check whether qla2xxx is loaded or present on target systems.
  • Review kernel logs for qla2xxx, bsg_done, or qlafwupdate crash traces.
  • Map installed kernels against vendor advisories and referenced stable commits.
  • Regression test storage connectivity after kernel updates.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-71238 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
9Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910, 1b81e7f3019d632a707e07927e946ffbbc102910unaffected
LinuxLinux5.7, 0, 5.10.251, 5.15.201, 6.1.164, 6.6.127, 6.12.74, 6.18.13, 6.19.3, 7.0affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.