cbcvebase.
CVE-2025-71236
published 2026-02-18

CVE-2025-71236: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associated memory System crash with the following…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associated memory System crash with the following signature [154563.214890] nvme nvme2: NVME-FC{1}: controller connect complete [154564.169363] qla2xxx [0000:b0:00.1]-3002:2: nvme: Sched: Set ZIO exchange threshold to 3. [154564.169405] qla2xxx [0000:b0:00.1]-ffffff:2: SET ZIO Activity exchange threshold to 5. [154565.539974] qla2xxx [0000:b0:00.1]-5013:2: RSCN database changed – 0078 0080 0000. [154565.545744] qla2xxx [0000:b0:00.1]-5013:2: RSCN database changed – 0078 00a0 0000. [154565.545857] qla2xxx [0000:b0:00.1]-11a2:2: FEC=enabled (data rate). [154565.552760] qla2xxx [0000:b0:00.1]-11a2:2: FEC=enabled (data rate). [154565.553079] BUG: kernel NULL pointer dereference, address: 00000000000000f8 [154565.553080] #PF: supervisor read access in kernel mode [154565.553082] #PF: error_code(0x0000) - not-present page [154565.553084] PGD 80000010488ab067 P4D 80000010488ab067 PUD 104978a067 PMD 0 [154565.553089] Oops: 0000 1 PREEMPT SMP PTI [154565.553092] CPU: 10 PID: 858 Comm: qla2xxx_2_dpc Kdump: loaded Tainted: G OE ------- --- 5.14.0-503.11.1.el9_5.x86_64 #1 [154565.553096] Hardware name: HPE Synergy 660 Gen10/Synergy 660 Gen10 Compute Module, BIOS I43 09/30/2024 [154565.553097] RIP: 0010:qla_fab_async_scan.part.0+0x40b/0x870 [qla2xxx] [154565.553141] Code: 00 00 e8 58 a3 ec d4 49 89 e9 ba 12 20 00 00 4c 89 e6 49 c7 c0 00 ee a8 c0 48 c7 c1 66 c0 a9 c0 bf 00 80 00 10 e8 15 69 00 00 8b 8d f8 00 00 00 4d 85 c9 74 35 49 8b 84 24 00 19 00 00 48 8b [154565.553143] RSP: 0018:ffffb4dbc8aebdd0 EFLAGS: 00010286 [154565.553145] RAX: 0000000000000000 RBX: ffff8ec2cf0908d0 RCX: 0000000000000002 [154565.553147] RDX: 0000000000000000 RSI: ffffffffc0a9c896 RDI: ffffb4dbc8aebd47 [154565.553148] RBP: 0000000000000000 R08: ffffb4dbc8aebd45 R09: 0000000000ffff0a [154565.553150] R10: 0000000000000000 R11: 000000000000000f R12: ffff8ec2cf0908d0 [154565.553151] R13: ffff8ec2cf

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 85c0890fea6baeba9c4ae6ae090182cbb1a93fb285c0890fea6baeba9c4ae6ae090182cbb1a93fb2
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < a46f81c1e627437de436e517f5fd4b725c15a1e6a46f81c1e627437de436e517f5fd4b725c15a1e6
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 044131fce27749cb6ea986baf861fbe63c6d8a17044131fce27749cb6ea986baf861fbe63c6d8a17
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 949010291bb941d53733ed08a33454254d9afb1b949010291bb941d53733ed08a33454254d9afb1b
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 40ae93668226b610edb952c6036f607a61750b5740ae93668226b610edb952c6036f607a61750b57
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 1a9585e4c58d1f1662b3ca46110ed4f583082ce51a9585e4c58d1f1662b3ca46110ed4f583082ce5
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 944378ead9a48d5d50e9e3cc85e4cdb911c37ca1944378ead9a48d5d50e9e3cc85e4cdb911c37ca1
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < b6df15aec8c3441357d4da0eaf4339eb20f5999fb6df15aec8c3441357d4da0eaf4339eb20f5999f
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1
linuxlinux_kernel>= 4.16 < 5.10.2515.10.251
linuxlinux_kernel>= 5.11 < 5.15.2015.15.201
linuxlinux_kernel>= 5.16 < 6.1.1646.1.164
linuxlinux_kernel>= 6.13 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
linuxlinux_kernel>= 6.2 < 6.6.1256.6.125
linuxlinux_kernel>= 6.7 < 6.12.726.12.72
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_msrc7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.