CVE-2023-54108
published 2025-12-24CVE-2023-54108: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message and call…
PriorityP421low2.5
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0910a791a6d7fd331f231f48200e18babb519769 < e596253113b69b4018818260bd5da40c201bee73 | e596253113b69b4018818260bd5da40c201bee73 |
| linux | linux | >= 2d087c7e55db420107c3ea97b228e067a7b488a1 < 3a564de3a299856f2cbd289649cea2e20d671a43 | 3a564de3a299856f2cbd289649cea2e20d671a43 |
| linux | linux | >= 5.10.110 < 5.10.173 | 5.10.173 |
| linux | linux | >= 5.15.33 < 5.15.99 | 5.15.99 |
| linux | linux | >= 5.16.19 < 5.17 | 5.17 |
| linux | linux | >= 5.17.2 < 5.18 | 5.18 |
| linux | linux | >= 5.4.189 < 5.4.235 | 5.4.235 |
| linux | linux | >= c85ab7d9e27a80e48d5b7d7fb2fe2b0fdb2de523 < 3ee4f1991c54c6707aa9df47e51c02ea25bb63e3 | 3ee4f1991c54c6707aa9df47e51c02ea25bb63e3 |
| linux | linux | >= c85ab7d9e27a80e48d5b7d7fb2fe2b0fdb2de523 < ad6af23593594402c826eefdf43ae174e5f0f202 | ad6af23593594402c826eefdf43ae174e5f0f202 |
| linux | linux | >= c85ab7d9e27a80e48d5b7d7fb2fe2b0fdb2de523 < c75e6aef5039830cce5d4cf764dd204522f89e6b | c75e6aef5039830cce5d4cf764dd204522f89e6b |
| linux | linux | >= c9d6081a5f18286ad62afc1e9e06a90cfd626902 < 77302fb0e357da666d5249a6e91078feeef3dade | 77302fb0e357da666d5249a6e91078feeef3dade |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11.0 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.18.0 < 6.2.3 | 6.2.3 |
| linux | linux_kernel | >= 5.5.0 < 5.10.173 | 5.10.173 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w45h-m4r8-m765: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message
ghsa_unreviewed·2025-12-24
CVE-2023-54108 GHSA-w45h-m4r8-m765: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
OSV
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
osv·2025-12-24
CVE-2023-54108 scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
OSV
CVE-2023-54108: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message an
osv·2025-12-24
CVE-2023-54108 CVE-2023-54108: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message an
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message and call trace was seen with debug kernels: DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as single] WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017 check_unmap+0xf42/0x1990 Call Trace: debug_dma_unmap_page+0xc9/0x100 qla_nvme_ls_unmap+0x141/0x210 [qla2xxx] Remove DMA mapping from the driver altogether, as it is already done by FC layer. This prevents the warning.
Red Hat
kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
vendor_redhat·2025-12-24·CVSS 2.5
CVE-2023-54108 [LOW] CWE-763 kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
Statement: This vulnerability is rated Low for Red Hat Enterprise Linux 8 and 9. The flaw in the `qla2xxx` SCSI driver can le
Debian
CVE-2023-54108: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
vendor_debian·2023
CVE-2023-54108 CVE-2023-54108: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message and call trace was seen with debug kernels: DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as single] WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017 check_unmap+0xf42/0x1990 Call Trace: debug_dma_unmap_page+0xc9/0x100 qla_nvme_ls_unmap+0x141/0x210 [qla2xxx] Remove DMA mapping from the driver altogether, as it is already done by FC layer. This prevents the warning.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54108 kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
bugzilla·2025-12-24
CVE-2023-54108 [LOW] CVE-2023-54108 kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
CVE-2023-54108 kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122412-CVE-2023-54108-d5be
Wiz
CVE-2023-54108 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54108 CVE-2023-54108 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54108 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests
The following message and call trace was seen with debug kernels:
DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map
error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as
single]
WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017
check_unmap+0xf42/0x1990
Call Trace:
debug_dma_unmap_page+0xc9/0x100
qla_nvme_ls_unmap+0x141/0x210 [qla2xxx]
Remove DMA mapping from the driver altogether, as it is already done by FC
layer. This prevents the warning.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has P
https://git.kernel.org/stable/c/3a564de3a299856f2cbd289649cea2e20d671a43https://git.kernel.org/stable/c/3ee4f1991c54c6707aa9df47e51c02ea25bb63e3https://git.kernel.org/stable/c/77302fb0e357da666d5249a6e91078feeef3dadehttps://git.kernel.org/stable/c/ad6af23593594402c826eefdf43ae174e5f0f202https://git.kernel.org/stable/c/c75e6aef5039830cce5d4cf764dd204522f89e6bhttps://git.kernel.org/stable/c/e596253113b69b4018818260bd5da40c201bee73
2025-12-24
Published