CVE-2023-54011
published 2025-12-24CVE-2023-54011: In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix an issue found by KASAN Write only correct size (32 instead of 64 bytes).
PriorityP418low5.5
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 42fc9fee116fc6a225a1f738adf86689d5c39d49 < abfe73c16b295f2213e9bfc0a1df232056032448 | abfe73c16b295f2213e9bfc0a1df232056032448 |
| linux | linux | >= 42fc9fee116fc6a225a1f738adf86689d5c39d49 < c8755f913a2fc9c168d108ea8c5af04716e8c4a5 | c8755f913a2fc9c168d108ea8c5af04716e8c4a5 |
| linux | linux | >= 42fc9fee116fc6a225a1f738adf86689d5c39d49 < ae7d45f5283d30274039b95d3e6d53d33c66e991 | ae7d45f5283d30274039b95d3e6d53d33c66e991 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 6.1.0 < 6.1.18 | 6.1.18 |
| linux | linux_kernel | >= 6.2.0 < 6.2.5 | 6.2.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54011: In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix an issue found by KASAN Write only correct size (32 instead of 6
osv·2025-12-24
CVE-2023-54011 CVE-2023-54011: In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix an issue found by KASAN Write only correct size (32 instead of 6
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix an issue found by KASAN Write only correct size (32 instead of 64 bytes).
GHSA
GHSA-v87f-6285-pqgv: In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of
ghsa_unreviewed·2025-12-24
CVE-2023-54011 GHSA-v87f-6285-pqgv: In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
OSV
scsi: mpi3mr: Fix an issue found by KASAN
osv·2025-12-24
CVE-2023-54011 scsi: mpi3mr: Fix an issue found by KASAN
scsi: mpi3mr: Fix an issue found by KASAN
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
Red Hat
kernel: scsi: mpi3mr: Fix an issue found by KASAN
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54011 [LOW] CWE-805 kernel: scsi: mpi3mr: Fix an issue found by KASAN
kernel: scsi: mpi3mr: Fix an issue found by KASAN
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
A flaw was found in the Linux kernel's mpi3mr SCSI driver for Broadcom MPI3 HBA controllers. The driver writes 64 bytes when only 32 bytes should be written, causing an out-of-bounds write detected by KASAN. This memory corruption could lead to system instability or a kernel crash.
Statement: This vulnerability affects systems with Broadcom MPI3 MegaRAID or HBA controllers using the mpi3mr driver. The out-of-bounds write is limited to a specific operation within the driver. Systems without this hardware are not affected.
Package: kernel (Red Hat Enterprise Linux 10) - Not affecte
Debian
CVE-2023-54011: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3m...
vendor_debian·2023
CVE-2023-54011 CVE-2023-54011: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3m...
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix an issue found by KASAN Write only correct size (32 instead of 64 bytes).
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54011 kernel: scsi: mpi3mr: Fix an issue found by KASAN
bugzilla·2025-12-24
CVE-2023-54011 [LOW] CVE-2023-54011 kernel: scsi: mpi3mr: Fix an issue found by KASAN
CVE-2023-54011 kernel: scsi: mpi3mr: Fix an issue found by KASAN
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122430-CVE-2023-54011-258c@gregkh/T
Wiz
CVE-2023-54011 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54011 CVE-2023-54011 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54011 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Fix an issue found by KASAN
Write only correct size (32 instead of 64 bytes).
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-debug-devel-matched
kernel-rt-debug-kvm
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Red Hat 8 Severity LOW Has Fix Added at: Dec 26, 2025
Red Hat 9 Severity LOW Has
2025-12-24
Published