CVE-2023-54014
published 2025-12-24CVE-2023-54014: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported warning of…
PriorityP419low5.5
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < f35bd94b4e11c41de90cd0fa72c9062e8196822f | f35bd94b4e11c41de90cd0fa72c9062e8196822f |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < ccd3bc595bda67db5a347b9050c2df28f292d3fb | ccd3bc595bda67db5a347b9050c2df28f292d3fb |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < 1b7e5bdf2be22ae8c61bdca5a5f96ec2746e9639 | 1b7e5bdf2be22ae8c61bdca5a5f96ec2746e9639 |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < 921d6844625527a92d1178262a633cc88a8e61bd | 921d6844625527a92d1178262a633cc88a8e61bd |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < 1ccd52b790a66b8b5f75c87eab8c3a37f941a2bf | 1ccd52b790a66b8b5f75c87eab8c3a37f941a2bf |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < e466930717ef18c112585a39fc6174d8eb441df5 | e466930717ef18c112585a39fc6174d8eb441df5 |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < ced5460eae772e847debbc0b65ef93aedab92d3f | ced5460eae772e847debbc0b65ef93aedab92d3f |
| linux | linux | >= 75cc8cfc6e13d42d50c2bf4307d0a68c2a70f709 < af73f23a27206ffb3c477cac75b5fcf03410556e | af73f23a27206ffb3c477cac75b5fcf03410556e |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 4.10.0 < 4.14.322 | 4.14.322 |
| linux | linux_kernel | >= 4.15.0 < 4.19.291 | 4.19.291 |
| linux | linux_kernel | >= 4.20.0 < 5.4.251 | 5.4.251 |
| linux | linux_kernel | >= 5.11.0 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16.0 < 6.1.40 | 6.1.40 |
| linux | linux_kernel | >= 5.5.0 < 5.10.188 | 5.10.188 |
| linux | linux_kernel | >= 6.2.0 < 6.4.5 | 6.4.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54014: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported w
osv·2025-12-24
CVE-2023-54014 CVE-2023-54014: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported w
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported warning of rport maybe NULL and will be dereferenced. rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced. Check valid rport returned by fc_bsg_to_rport().
GHSA
GHSA-rvc2-c2hh-3j58: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported
ghsa_unreviewed·2025-12-24
CVE-2023-54014 GHSA-rvc2-c2hh-3j58: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
OSV
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
osv·2025-12-24
CVE-2023-54014 scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
Red Hat
kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54014 [LOW] CWE-476 kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 9) - Fix deferred
Debian
CVE-2023-54014: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
vendor_debian·2023
CVE-2023-54014 CVE-2023-54014: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport() Klocwork reported warning of rport maybe NULL and will be dereferenced. rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced. Check valid rport returned by fc_bsg_to_rport().
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.4.11-1)
trixie: resolved (fixed in 6.4.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54014 kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
bugzilla·2025-12-24
CVE-2023-54014 [LOW] CVE-2023-54014 kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
CVE-2023-54014 kernel: scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122431-CVE-2023-54014-9b8c@gregkh/T
Wiz
CVE-2023-54014 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54014 CVE-2023-54014 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54014 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Check valid rport returned by fc_bsg_to_rport()
Klocwork reported warning of rport maybe NULL and will be dereferenced.
rport returned by call to fc_bsg_to_rport() could be NULL and dereferenced.
Check valid rport returned by fc_bsg_to_rport().
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-abi-whitelists
kernel-ipaclones-internal
Sources
NVD
Debia
https://git.kernel.org/stable/c/1b7e5bdf2be22ae8c61bdca5a5f96ec2746e9639https://git.kernel.org/stable/c/1ccd52b790a66b8b5f75c87eab8c3a37f941a2bfhttps://git.kernel.org/stable/c/921d6844625527a92d1178262a633cc88a8e61bdhttps://git.kernel.org/stable/c/af73f23a27206ffb3c477cac75b5fcf03410556ehttps://git.kernel.org/stable/c/ccd3bc595bda67db5a347b9050c2df28f292d3fbhttps://git.kernel.org/stable/c/ced5460eae772e847debbc0b65ef93aedab92d3fhttps://git.kernel.org/stable/c/e466930717ef18c112585a39fc6174d8eb441df5https://git.kernel.org/stable/c/f35bd94b4e11c41de90cd0fa72c9062e8196822f
2025-12-24
Published