CVE-2023-53066
published 2025-05-02CVE-2023-53066: In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make sure that…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to make sure that the info returned by the helper is valid
before using it.
Found by Linux Verification Center (linuxtesting.org) with the SVACE
static analysis tool.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 7bd0037822fd04da13721f77a42ee5a077d4c5fb | 7bd0037822fd04da13721f77a42ee5a077d4c5fb |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 7742c08e012eb65405e8304d100641638c5ff882 | 7742c08e012eb65405e8304d100641638c5ff882 |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 42d72c6d1edc9dc09a5d6f6695d257fa9e9cc270 | 42d72c6d1edc9dc09a5d6f6695d257fa9e9cc270 |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 39c3b9dd481c3afce9439b29bafe00444cb4406b | 39c3b9dd481c3afce9439b29bafe00444cb4406b |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < e42d3bde4ec03c863259878dddaef5c351cca7ad | e42d3bde4ec03c863259878dddaef5c351cca7ad |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 97ea704f39b5ded96f071e98701aa543f6f89683 | 97ea704f39b5ded96f071e98701aa543f6f89683 |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < b224b0cab3a66e93d414825065a2e667a1d28c32 | b224b0cab3a66e93d414825065a2e667a1d28c32 |
| linux | linux | >= 733def6a04bf3d2810dd675e1240f8df94d633c3 < 25143b6a01d0cc5319edd3de22ffa2578b045550 | 25143b6a01d0cc5319edd3de22ffa2578b045550 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 4.15 < 4.19.280 | 4.19.280 |
| linux | linux_kernel | >= 4.20 < 5.4.240 | 5.4.240 |
| linux | linux_kernel | >= 4.7 < 4.14.312 | 4.14.312 |
| linux | linux_kernel | >= 5.11 < 5.15.105 | 5.15.105 |
| linux | linux_kernel | >= 5.16 < 6.1.22 | 6.1.22 |
| linux | linux_kernel | >= 5.5 < 5.10.177 | 5.10.177 |
| linux | linux_kernel | >= 6.2 < 6.2.9 | 6.2.9 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fhjp-7gr5-7mh5: In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to mak
ghsa_unreviewed·2025-05-02
CVE-2023-53066 [MEDIUM] CWE-476 GHSA-fhjp-7gr5-7mh5: In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to mak
In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to make sure that the info returned by the helper is valid
before using it.
Found by Linux Verification Center (linuxtesting.org) with the SVACE
static analysis tool.
OSV
CVE-2023-53066: In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make
osv·2025-05-02·CVSS 5.5
CVE-2023-53066 [MEDIUM] CVE-2023-53066: In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make
In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make sure that the info returned by the helper is valid before using it. Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.
Red Hat
kernel: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
vendor_redhat·2025-05-02·CVSS 5.5
CVE-2023-53066 [MEDIUM] CWE-476 kernel: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
kernel: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to make sure that the info returned by the helper is valid
before using it.
Found by Linux Verification Center (linuxtesting.org) with the SVACE
static analysis tool.
A flaw was found in the QED SR-IOV support in the Linux kernel. Improper validation of the value returned from the qed_iov_get_vf_info function can cause a NULL pointer dereference and result in a denial of service.
Statement: This issue has been fixed in Red Hat Enterprise Linux 9.6 via RHSA-2025:6966 [1].
[1]. https://access.redhat.com/errata/RHSA-2025:6966
Package: kernel (Red Hat Enterprise Linux 10) - Not
Debian
CVE-2023-53066: linux - In the Linux kernel, the following vulnerability has been resolved: qed/qed_sri...
vendor_debian·2023·CVSS 5.5
CVE-2023-53066 [MEDIUM] CVE-2023-53066: linux - In the Linux kernel, the following vulnerability has been resolved: qed/qed_sri...
In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make sure that the info returned by the helper is valid before using it. Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/25143b6a01d0cc5319edd3de22ffa2578b045550https://git.kernel.org/stable/c/39c3b9dd481c3afce9439b29bafe00444cb4406bhttps://git.kernel.org/stable/c/42d72c6d1edc9dc09a5d6f6695d257fa9e9cc270https://git.kernel.org/stable/c/7742c08e012eb65405e8304d100641638c5ff882https://git.kernel.org/stable/c/7bd0037822fd04da13721f77a42ee5a077d4c5fbhttps://git.kernel.org/stable/c/97ea704f39b5ded96f071e98701aa543f6f89683https://git.kernel.org/stable/c/b224b0cab3a66e93d414825065a2e667a1d28c32https://git.kernel.org/stable/c/e42d3bde4ec03c863259878dddaef5c351cca7ad
2025-05-02
Published