CVE-2025-68745

Source
https://cve.org/CVERecord?id=CVE-2025-68745
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68745.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68745
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
ECHO (1)
OESA (5)
openSUSE (3)
RHSA (4)
RLSA (4)
ROOT (5)
SUSE (4)
UBUNTU (1)
Related
Published
2025-12-24T12:09:41Z
Modified
2026-10-08T02:51:11Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
scsi: qla2xxx: Clear cmds after chip reset
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Clear cmds after chip reset

Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling and host reset handling") caused two problems:

  1. Commands sent to FW, after chip reset got stuck and never freed as FW is not going to respond to them anymore.

  2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a ("scsi: qla2xxx: Fix missed DMA unmap for aborted commands") attempted to fix this, but introduced another bug under different circumstances when two different CPUs were racing to call qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in dma_unmap_sg_attrs().

So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and partially revert "scsi: qla2xxx: target: Fix offline port handling and host reset handling" at __qla2x00_abort_all_cmds.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68745.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
aefed3e5548f28e5fecafda6604fcbc65484dbaa
Fixed
5c1fb3fd05da3d55b8cbc42d7d660b313cbdc936
Fixed
d46c69a087aa3d1513f7a78f871b80251ea0c1ae
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.9.316
Fixed
4.10
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.14.281
Fixed
4.15
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4.19.245
Fixed
4.20
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
eb67b7a23d357f578578e737cb6412ae2384f352
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec9639d92c1e10d4bc667e842753d85e21683d5c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e6e957f552d5b696879a31e5b0e2a9120e1ea86e

Affected versions

v4.*
v4.14.281
v4.14.282
v4.14.283
v4.14.284
v4.14.285
v4.14.286
v4.14.287
v4.14.288
v4.14.289
v4.14.290
v4.14.291
v4.14.292
v4.14.293
v4.14.294
v4.14.295
v4.14.296
v4.14.297
v4.14.298
v4.14.299
v4.14.300
v4.14.301
v4.14.302
v4.14.303
v4.14.304
v4.14.305
v4.14.306
v4.14.307
v4.14.308
v4.14.309
v4.14.310
v4.14.311
v4.14.312
v4.14.313
v4.14.314
v4.14.315
v4.14.316
v4.14.317
v4.14.318
v4.14.319
v4.14.320
v4.14.321
v4.14.322
v4.14.323
v4.14.324
v4.14.325
v4.14.326
v4.14.327
v4.14.328
v4.14.329
v4.14.330
v4.14.331
v4.14.332
v4.14.333
v4.14.334
v4.14.335
v4.14.336
v4.19.245
v4.19.246
v4.19.247
v4.19.248
v4.19.249
v4.19.250
v4.19.251
v4.19.252
v4.19.253
v4.19.254
v4.19.255
v4.19.256
v4.19.257
v4.19.258
v4.19.259
v4.19.260
v4.19.261
v4.19.262
v4.19.263
v4.19.264
v4.19.265
v4.19.266
v4.19.267
v4.19.268
v4.19.269
v4.19.270
v4.19.271
v4.19.272
v4.19.273
v4.19.274
v4.19.275
v4.19.276
v4.19.277
v4.19.278
v4.19.279
v4.19.280
v4.19.281
v4.19.282
v4.19.283
v4.19.284
v4.19.285
v4.19.286
v4.19.287
v4.19.288
v4.19.289
v4.19.290
v4.19.291
v4.19.292
v4.19.293
v4.19.294
v4.19.295
v4.19.296
v4.19.297
v4.19.298
v4.19.299
v4.19.300
v4.19.301
v4.19.302
v4.19.303
v4.19.304
v4.19.305
v4.19.306
v4.19.307
v4.19.308
v4.19.309
v4.19.310
v4.19.311
v4.19.312
v4.19.313
v4.19.314
v4.19.315
v4.19.316
v4.19.317
v4.19.318
v4.19.319
v4.19.320
v4.19.321
v4.19.322
v4.19.323
v4.19.324
v4.19.325
v4.9.316
v4.9.317
v4.9.318
v4.9.319
v4.9.320
v4.9.321
v4.9.322
v4.9.323
v4.9.324
v4.9.325
v4.9.326
v4.9.327
v4.9.328
v4.9.329
v4.9.330
v4.9.331
v4.9.332
v4.9.333
v4.9.334
v4.9.335
v4.9.336
v4.9.337

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68745.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
6.18.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68745.json"