cbcvebase.
CVE-2023-53754
published 2025-12-08

CVE-2023-53754: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() When if_type equals zero and…

PriorityP419low5.5
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix ioremap issues in lpfc_sli4_pci_mem_setup() When if_type equals zero and pci_resource_start(pdev, PCI_64BIT_BAR4) returns false, drbl_regs_memmap_p is not remapped. This passes a NULL pointer to iounmap(), which can trigger a WARN() on certain arches. When if_type equals six and pci_resource_start(pdev, PCI_64BIT_BAR4) returns true, drbl_regs_memmap_p may has been remapped and ctrl_regs_memmap_p is not remapped. This is a resource leak and passes a NULL pointer to iounmap(). To fix these issues, we need to add null checks before iounmap(), and change some goto labels.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < 74d90f92eafe8ccd12827228236a28a94eda6bcc74d90f92eafe8ccd12827228236a28a94eda6bcc
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < bab8dc38b1a0a12bc064fc064269033bdcf5b88ebab8dc38b1a0a12bc064fc064269033bdcf5b88e
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < fd8c83d8375b9dac1949f2753485a5c055ebfad0fd8c83d8375b9dac1949f2753485a5c055ebfad0
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < e6f1ef4a53856ed000b0f7265d7e16dcb00f4243e6f1ef4a53856ed000b0f7265d7e16dcb00f4243
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < 631d0fab143bef85ea0813596f1dda36e2b9724c631d0fab143bef85ea0813596f1dda36e2b9724c
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < 7e5a54d1f00725a739dcd20f616d82eff4f764bd7e5a54d1f00725a739dcd20f616d82eff4f764bd
linuxlinux>= 1351e69fc6db30e186295f1c9495d03cef6a01a2 < 91a0c0c1413239d0548b5aac4c82f38f6d53a91e91a0c0c1413239d0548b5aac4c82f38f6d53a91e
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.17.0 < 5.4.2435.4.243
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 5.5.0 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.