CVE-2025-68745 — Race Condition within a Thread in Linux
Severity
6.4MEDIUM
No vectorEPSS
0.0%
top 92.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateApr 17
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Clear cmds after chip reset
Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling
and host reset handling") caused two problems:
1. Commands sent to FW, after chip reset got stuck and never freed as FW
is not going to respond to them anymore.
2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a
("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
attempted to fix this, but …
Affected Packages13 packages
🔴Vulnerability Details
3OSV▶
CVE-2025-68745: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit aefed3e5548f ("scsi: qla2xxx: ta↗2025-12-24
GHSA▶
GHSA-vc2w-h9rc-mpxx: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Clear cmds after chip reset
Commit aefed3e5548f ("scsi: qla2xxx:↗2025-12-24
📋Vendor Advisories
6Red Hat▶
kernel: Linux kernel: Denial of Service in qla2xxx SCSI driver due to improper command handling after chip reset↗2025-12-24