What happened
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean up the allocated memory for the management command.
Affected versions
Linux: 1c5bf7c529d95755f32b8ef449d10df2d50aaf5a through before 29a22a3d495c147117137719d2c39045c44ccebf (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 89df49e561b4a8948521fc3f8a013012eaa08f82 (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 6a4236ed47f5b0a57eb6b8fb1c351b15b3d341d7 (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 601be20fc6a1b762044d2398befffd6bf236cebf (git); 5.11 Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.