CVE-2025-71236
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71236 is a NULL pointer dereference vulnerability in the Linux kernel's qla2xxx SCSI driver, specifically in the qla_fab_async_scan function, where the driver attempts to free memory associated with a storage protocol (sp) pointer without first validating that the pointer is non-NULL. It affects Linux kernel versions from 4.16 through multiple stable branches up to 6.19. The vulnerability was published on February 18, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, Microsoft MSRC).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference). Within the qla_fab_async_scan function of the qla2xxx driver, the code proceeds to dereference and free memory associated with an sp (storage protocol) pointer without first checking whether the pointer is NULL. This flaw is triggered during NVMe-FC controller activity and Fibre Channel topology change events (RSCN events), causing a kernel NULL pointer dereference at address 0x00000000000000f8. The attack vector is local, requiring low privileges and no user interaction, making it exploitable by any local user on a system running the affected driver (Feedly).

Impact

Successful exploitation results in a kernel panic (Oops) and system crash, causing a complete denial of service on the affected host. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Systems using qla2xxx-based Fibre Channel HBAs (e.g., HPE Synergy hardware) in NVMe-FC environments are particularly at risk, as the crash can be triggered during normal storage operations (Feedly).

Indicators of compromise

  • Logs: Kernel log entries containing BUG: kernel NULL pointer dereference, address: 00000000000000f8 and RIP: 0010:qla_fab_async_scan.part.0 in /var/log/kern.log or dmesg output.
  • Logs: Messages from the qla2xxx driver such as RSCN database changed immediately preceding a kernel Oops in system logs.
  • Logs: Kernel crash dump (kdump) files generated following an unexpected system reboot on hosts with qla2xxx HBAs.
  • Process: Unexpected termination or crash of the qla2xxx_X_dpc kernel thread (e.g., qla2xxx_2_dpc, PID visible in crash trace).

Mitigation and workarounds

Update the Linux kernel to a patched stable version appropriate for your branch: 5.10.251 or later (for 4.16–5.10.x), 5.15.201 or later (for 5.11–5.15.x), 6.1.164 or later (for 5.16–6.1.x), 6.6.125 or later (for 6.2–6.6.x), 6.12.72 or later (for 6.7–6.12.x), 6.18.11 or later (for 6.13–6.18.x), and 6.19.1 or later (for 6.19.x). Patches are available via the Linux kernel stable tree and have been incorporated into Debian (DSA-6163-1, DLA-4499-1), SUSE (SUSE-2026-0962-1), Oracle Linux (ELSA-2026-50160, ELSA-2026-50232), and Amazon Linux 2 (ALAS2KERNEL-5.10-2026-114) advisories. As a temporary workaround where patching is not immediately possible, consider unloading the qla2xxx module if the hardware is not in active use, though this will disable associated storage connectivity (Feedly, Microsoft MSRC).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management