cbcvebase.
CVE-2023-54179
published 2025-12-30

CVE-2023-54179: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of…

PriorityP421medium6.6
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of size 16 may use index value(s) 16..19. Use snprintf() instead of sprintf().

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e697f466bf61280b7e996c9ea096d7ec371c31eae697f466bf61280b7e996c9ea096d7ec371c31ea
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ea64c727f20123342020257cfa956fbfbd6d12ffea64c727f20123342020257cfa956fbfbd6d12ff
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bcd773969a87d9802053c0db5be84abd6594a024bcd773969a87d9802053c0db5be84abd6594a024
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 748d8f8698a2f48ffe32dd7b35dbab1810ed1f82748d8f8698a2f48ffe32dd7b35dbab1810ed1f82
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2b3bdef089b920b4a19fefb4f4e6dda56a4bb5832b3bdef089b920b4a19fefb4f4e6dda56a4bb583
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e934737e18ff069a66cd53cd7f7a0b34ae2c24fee934737e18ff069a66cd53cd7f7a0b34ae2c24fe
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d721b591b95cf3f290f8a7cbe90aa2ee0368388dd721b591b95cf3f290f8a7cbe90aa2ee0368388d
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 2.6.12 < 4.19.2914.19.291
linuxlinux_kernel>= 4.20.0 < 5.4.2535.4.253
linuxlinux_kernel>= 5.11.0 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16.0 < 6.1.406.1.40
linuxlinux_kernel>= 5.5.0 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2.0 < 6.4.56.4.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.