CVE-2023-54179
published 2025-12-30CVE-2023-54179: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of…
PriorityP421medium6.6
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e697f466bf61280b7e996c9ea096d7ec371c31ea | e697f466bf61280b7e996c9ea096d7ec371c31ea |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ea64c727f20123342020257cfa956fbfbd6d12ff | ea64c727f20123342020257cfa956fbfbd6d12ff |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bcd773969a87d9802053c0db5be84abd6594a024 | bcd773969a87d9802053c0db5be84abd6594a024 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 748d8f8698a2f48ffe32dd7b35dbab1810ed1f82 | 748d8f8698a2f48ffe32dd7b35dbab1810ed1f82 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2b3bdef089b920b4a19fefb4f4e6dda56a4bb583 | 2b3bdef089b920b4a19fefb4f4e6dda56a4bb583 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e934737e18ff069a66cd53cd7f7a0b34ae2c24fe | e934737e18ff069a66cd53cd7f7a0b34ae2c24fe |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d721b591b95cf3f290f8a7cbe90aa2ee0368388d | d721b591b95cf3f290f8a7cbe90aa2ee0368388d |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 2.6.12 < 4.19.291 | 4.19.291 |
| linux | linux_kernel | >= 4.20.0 < 5.4.253 | 5.4.253 |
| linux | linux_kernel | >= 5.11.0 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16.0 < 6.1.40 | 6.1.40 |
| linux | linux_kernel | >= 5.5.0 < 5.10.188 | 5.10.188 |
| linux | linux_kernel | >= 6.2.0 < 6.4.5 | 6.4.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.4.4 scsi snprintf array index (Nessus ID 319480 / WID-SEC-2025-2941)
vuldb·2026-06-07
CVE-2023-54179 [CRITICAL] Linux Kernel up to 6.4.4 scsi snprintf array index (Nessus ID 319480 / WID-SEC-2025-2941)
A vulnerability was found in Linux Kernel up to 6.4.4. It has been declared as critical. The affected element is the function snprintf of the component scsi. Such manipulation leads to improper validation of array index.
This vulnerability is referenced as CVE-2023-54179. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
OSV
scsi: qla2xxx: Array index may go out of bound
osv·2025-12-30
CVE-2023-54179 scsi: qla2xxx: Array index may go out of bound
scsi: qla2xxx: Array index may go out of bound
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
OSV
CVE-2023-54179: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_s
osv·2025-12-30
CVE-2023-54179 CVE-2023-54179: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_s
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of size 16 may use index value(s) 16..19. Use snprintf() instead of sprintf().
GHSA
GHSA-39wf-xfc6-2r64: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host
ghsa_unreviewed·2025-12-30
CVE-2023-54179 GHSA-39wf-xfc6-2r64: In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
Red Hat
kernel: scsi: qla2xxx: Array index may go out of bound
vendor_redhat·2025-12-30·CVSS 6.6
CVE-2023-54179 [MEDIUM] CWE-119 kernel: scsi: qla2xxx: Array index may go out of bound
kernel: scsi: qla2xxx: Array index may go out of bound
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
A flaw was found in the Linux kernel qla2xxx SCSI driver. A static analysis tool reported that the array vha->host_str, sized to hold 16 characters, could be indexed with values outside its valid range, potentially leading to out-of-bounds writes. The root cause was the use of sprintf() without enforcing proper bounds checks. An unprivileged local user with access to trigger the affected driver logic may be able to cause a kernel crash or hang, resulting in a denial of service.
Mitigation: Mitigation for
Debian
CVE-2023-54179: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
vendor_debian·2023
CVE-2023-54179 CVE-2023-54179: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: qla2x...
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of size 16 may use index value(s) 16..19. Use snprintf() instead of sprintf().
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.4.11-1)
trixie: resolved (fixed in 6.4.11-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54179 kernel: scsi: qla2xxx: Array index may go out of bound
bugzilla·2025-12-30
CVE-2023-54179 [MEDIUM] CVE-2023-54179 kernel: scsi: qla2xxx: Array index may go out of bound
CVE-2023-54179 kernel: scsi: qla2xxx: Array index may go out of bound
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123023-CVE-2023-54179-e6e3@gregkh/T
Wiz
CVE-2023-54179 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54179 CVE-2023-54179 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54179 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Array index may go out of bound
Klocwork reports array 'vha->host_str' of size 16 may use index value(s)
16..19. Use snprintf() instead of sprintf().
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-64kb-devel
kernel-docs-html
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Red Hat 6, 7 Severity M
https://git.kernel.org/stable/c/2b3bdef089b920b4a19fefb4f4e6dda56a4bb583https://git.kernel.org/stable/c/748d8f8698a2f48ffe32dd7b35dbab1810ed1f82https://git.kernel.org/stable/c/bcd773969a87d9802053c0db5be84abd6594a024https://git.kernel.org/stable/c/d721b591b95cf3f290f8a7cbe90aa2ee0368388dhttps://git.kernel.org/stable/c/e697f466bf61280b7e996c9ea096d7ec371c31eahttps://git.kernel.org/stable/c/e934737e18ff069a66cd53cd7f7a0b34ae2c24fehttps://git.kernel.org/stable/c/ea64c727f20123342020257cfa956fbfbd6d12ff
2025-12-30
Published