cbcvebase.
CVE-2023-53038
published 2025-05-02

CVE-2023-53038: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check kzalloc() in lpfc_sli4_cgn_params_read() If kzalloc() fails in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Check kzalloc() in lpfc_sli4_cgn_params_read() If kzalloc() fails in lpfc_sli4_cgn_params_read(), then we rely on lpfc_read_object()'s routine to NULL check pdata. Currently, an early return error is thrown from lpfc_read_object() to protect us from NULL ptr dereference, but the errno code is -ENODEV. Change the errno code to a more appropriate -ENOMEM.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 72df8a452883b0be334396acba07df77c3c3f6c7 < 67b8343998b84418bc5b5206aa01fe9b461a80ef67b8343998b84418bc5b5206aa01fe9b461a80ef
linuxlinux>= 72df8a452883b0be334396acba07df77c3c3f6c7 < 4829a1e1171536978b240a1438789c2e4d5c97154829a1e1171536978b240a1438789c2e4d5c9715
linuxlinux>= 72df8a452883b0be334396acba07df77c3c3f6c7 < 908dd9a0853a88155a5a36018c7e2b32ccf20379908dd9a0853a88155a5a36018c7e2b32ccf20379
linuxlinux>= 72df8a452883b0be334396acba07df77c3c3f6c7 < 312320b0e0ec21249a17645683fe5304d796aec1312320b0e0ec21249a17645683fe5304d796aec1
linuxlinux_kernel< 5.15.1055.15.105
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.16 < 6.1.226.1.22
linuxlinux_kernel>= 6.2 < 6.2.96.2.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.