CVE-2023-52508
published 2024-03-02CVE-2023-52508: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_op…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
The nvme_fc_fcp_op structure describing an AEN operation is initialized with a
null request structure pointer. An FC LLDD may make a call to
nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation.
Add validation of the request structure pointer before dereference.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5.18.18 < 5.19 | 5.19 |
| linux | linux | >= 827fc630e4c8087df5a8e8ee013b686bd6f13736 < be90c9e29dd59b7d19a73297a1590ff3ec1d22ea | be90c9e29dd59b7d19a73297a1590ff3ec1d22ea |
| linux | linux | >= 827fc630e4c8087df5a8e8ee013b686bd6f13736 < dd46b3ac7322baf3772b33b29726e94f98289db7 | dd46b3ac7322baf3772b33b29726e94f98289db7 |
| linux | linux | >= 827fc630e4c8087df5a8e8ee013b686bd6f13736 < 8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3c | 8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3c |
| linux | linux_kernel | < 6.1.56 | 6.1.56 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 6.2 < 6.5.6 | 6.5.6 |
| msrc | cbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
vendor_msrc·2024-03-12·CVSS 5.5
CVE-2023-52508 [MEDIUM] CWE-476 nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Red Hat
kernel: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
vendor_redhat·2024-03-02·CVSS 5.5
CVE-2023-52508 [MEDIUM] CWE-476 kernel: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
kernel: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
The nvme_fc_fcp_op structure describing an AEN operation is initialized with a
null request structure pointer. An FC LLDD may make a call to
nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation.
Add validation of the request structure pointer before dereference.
A vulnerability was found in the Linux kernel, caused by a NULL pointer dereference in the nvme_fc_io_getuuid() function. This issue could cause system instability and lead to a potential crash.
Mitigation: Mitigation for this issue is either not available or the currently available options do not m
Debian
CVE-2023-52508: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Pr...
vendor_debian·2023·CVSS 5.5
CVE-2023-52508 [MEDIUM] CVE-2023-52508: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Pr...
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_op structure describing an AEN operation is initialized with a null request structure pointer. An FC LLDD may make a call to nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation. Add validation of the request structure pointer before dereference.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
GHSA
GHSA-9mvw-qw27-cc95: In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
The nvme_fc_fc
ghsa_unreviewed·2024-03-03
CVE-2023-52508 [MEDIUM] CWE-476 GHSA-9mvw-qw27-cc95: In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
The nvme_fc_fc
In the Linux kernel, the following vulnerability has been resolved:
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
The nvme_fc_fcp_op structure describing an AEN operation is initialized with a
null request structure pointer. An FC LLDD may make a call to
nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation.
Add validation of the request structure pointer before dereference.
OSV
CVE-2023-52508: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_
osv·2024-03-02·CVSS 5.5
CVE-2023-52508 [MEDIUM] CVE-2023-52508: In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() The nvme_fc_fcp_op structure describing an AEN operation is initialized with a null request structure pointer. An FC LLDD may make a call to nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation. Add validation of the request structure pointer before dereference.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3chttps://git.kernel.org/stable/c/be90c9e29dd59b7d19a73297a1590ff3ec1d22eahttps://git.kernel.org/stable/c/dd46b3ac7322baf3772b33b29726e94f98289db7https://git.kernel.org/stable/c/8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3chttps://git.kernel.org/stable/c/be90c9e29dd59b7d19a73297a1590ff3ec1d22eahttps://git.kernel.org/stable/c/dd46b3ac7322baf3772b33b29726e94f98289db7
2024-03-02
Published