CVE-2023-54014NULL Pointer Dereference in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported warning of rport maybe NULL and will be dereferenced. rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced. Check valid rport returned by fc_bsg_to_rport().

Affected Packages4 packages

Linuxlinux/linux_kernel4.10.04.14.322+6
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709f35bd94b4e11c41de90cd0fa72c9062e8196822f+8
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2023-54014: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported w2025-12-24
GHSA
GHSA-rvc2-c2hh-3j58: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported2025-12-24
OSV
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()2025-12-24
Debian
CVE-2023-54014: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54014 Impact, Exploitability, and Mitigation Steps | Wiz