scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure If a call to lpfc_sli4_read_rev() from lpfc_sli4_hba_setup() fails, the resultant cleanup routine lpfc_sli4_vport_delete_fcp_xri_aborted() may occur before sli4_hba.hdwqs are allocated. This may result in a null pointer dereference when attempting to take the abts_io_buf_list_lock for the first hardware queue. Fix by adding a null ptr check on phba->sli4_hba.hdwq and early return because this situation means there must have been an error during port initialization.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-38695
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/6711ce7e9de4eb1a541ef30638df1294ea4267f8
- https://git.kernel.org/stable/c/74bdf54a847dab209d2a8f65852f59b7fa156175
- https://git.kernel.org/stable/c/5e25ee1ecec91c61a8acf938ad338399cad464de
- https://git.kernel.org/stable/c/add68606a01dcccf18837a53e85b85caf0693b4b
- https://git.kernel.org/stable/c/7925dd68807cc8fd755b04ca99e7e6f1c04392e8
- https://git.kernel.org/stable/c/571617f171f723b05f02d154a2e549a17eab4935
- https://git.kernel.org/stable/c/d3f55f46bb37a8ec73bfe3cfe36e3ecfa2945dfa
- https://git.kernel.org/stable/c/46a0602c24d7d425dd8e00c749cd64a934aac7ec
- https://git.kernel.org/stable/c/6698796282e828733cde3329c887b4ae9e5545e9
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.