cbcvebase.
CVE-2023-53124
published 2025-05-02

CVE-2023-53124: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add() Port is allocated by…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add() Port is allocated by sas_port_alloc_num() and rphy is allocated by either sas_end_device_alloc() or sas_expander_alloc(), all of which may return NULL. So we need to check the rphy to avoid possible NULL pointer access. If sas_rphy_add() returned with failure, rphy is set to NULL. We would access the rphy in the following lines which would also result NULL pointer access.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.10.163 < 5.10.1765.10.176
linuxlinux>= 5.15.86 < 5.15.1045.15.104
linuxlinux>= 5.4.229 < 5.4.2385.4.238
linuxlinux>= 6.0.16 < 6.16.1
linuxlinux>= 6.1.2 < 6.1.216.1.21
linuxlinux>= 6a92129c8f999ff5b122c100ce7f625eb3e98c4b < 9937f784a608944107dcc2ba9a9c3333f8330b9e9937f784a608944107dcc2ba9a9c3333f8330b9e
linuxlinux>= 78316e9dfc24906dd474630928ed1d3c562b568e < a26c775ccc4cfe46f9b718b51bd24313053c7e0ba26c775ccc4cfe46f9b718b51bd24313053c7e0b
linuxlinux>= 78316e9dfc24906dd474630928ed1d3c562b568e < d3c57724f1569311e4b81e98fad0931028b9bdcdd3c57724f1569311e4b81e98fad0931028b9bdcd
linuxlinux>= ce1a69cc85006b494353911b35171da195d79e25 < 6f0c2f70d9929208d8427ec72c3ed91e2251e2896f0c2f70d9929208d8427ec72c3ed91e2251e289
linuxlinux>= d17bca3ddfe507874cb826d32721552da12e741f < b5e5bbb3fa5f8412e96c5eda7f4a4af6241d6bd3b5e5bbb3fa5f8412e96c5eda7f4a4af6241d6bd3
linuxlinux>= d60000cb1195a464080b0efb4949daf7594e0020 < 090305c36185c0547e4441d4c08f1cf096b32134090305c36185c0547e4441d4c08f1cf096b32134
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.10.163 < 5.10.1765.10.176
linuxlinux_kernel>= 5.15.86 < 5.15.1045.15.104
linuxlinux_kernel>= 5.4.229 < 5.4.2385.4.238
linuxlinux_kernel>= 6.0.16 < 6.16.1
linuxlinux_kernel>= 6.1.2 < 6.1.216.1.21
linuxlinux_kernel>= 6.2 < 6.2.86.2.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.