A double-free vulnerability tracked as CVE-2025-71238 was disclosed in the Linux kernel's qla2xxx SCSI driver, affecting the block SCSI generic (bsg) interface used by vendor-specific handlers in qla_bsg.c. The flaw stems from inconsistent calls to bsg_done()/bsg_job_done() on both success and failure paths, allowing the same bsg job to be freed twice and potentially causing memory corruption. Kernel maintainers said the bug can trigger a kernel panic, and published crash details show faults during qla2x00_process_vendor_specific and qla24xx_bsg_request execution.
Red Hat rated the issue moderate severity and warned that a local attacker could exploit it to cause denial of service by crashing the kernel, with a theoretical chance of local privilege escalation; the flaw is not network reachable. Fixes were released in upstream stable and development kernel branches as well as multiple Red Hat Enterprise Linux kernel packages. Red Hat advised customers to apply updated kernel packages, while the kernel community recommended moving to the latest stable kernel; as a mitigation, Red Hat said systems can prevent the qla2xxx module from loading if immediate patching is not possible.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat marked the RHEL 10 kernel package as fixed for CVE-2025-71238 in advisory RHSA-2026:6053.
Red Hat published its advisory for CVE-2025-71238, describing a moderate-severity double-free vulnerability in the Linux kernel’s qla2xxx block SCSI generic interface that could let a local user crash the kernel and potentially achieve privilege escalation.
Kernel fixes validating state before calling bsg_done() were released for multiple branches, including 5.10.251, 5.15.201, 6.1.164, 6.6.127, 6.12.74, 6.18.13, 6.19.3, and 7.0-rc1. The advisory recommended updating to the latest stable kernel rather than cherry-picking commits.
The Linux kernel CVE team assigned CVE-2025-71238 to a double-free flaw in the qla2xxx SCSI driver’s bsg handling, where bsg_done() could be invoked on failure paths and lead to a kernel panic or memory corruption.
Red Hat marked the RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel package as fixed for CVE-2025-71238 in advisory RHSA-2026:14165.
Red Hat marked the RHEL 8.6 Advanced Mission Critical Update Support and Telecommunications Update Service kernel package as fixed for CVE-2025-71238 in advisory RHSA-2026:13664.
Red Hat marked the RHEL 7 Extended Lifecycle Support kernel-rt package as fixed for CVE-2025-71238 in advisory RHSA-2026:10756.
Red Hat marked the RHEL 7 Extended Lifecycle Support kernel package as fixed for CVE-2025-71238 in advisory RHSA-2026:9870.
Red Hat marked the RHEL 10.0 Extended Update Support kernel package as fixed for CVE-2025-71238 in advisory RHSA-2026:8342.
Red Hat marked both the RHEL 8 kernel package and the RHEL 8 kernel-rt package as fixed for CVE-2025-71238 in advisories RHSA-2026:6571 and RHSA-2026:6572.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.