CVE-2023-53280
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/09/2025
Last modified:
16/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue<br />
<br />
System crash when qla2x00_start_sp(sp) returns error code EGAIN and wake_up<br />
gets called for uninitialized wait queue sp->nvme_ls_waitq.<br />
<br />
qla2xxx [0000:37:00.1]-2121:5: Returning existing qpair of ffff8ae2c0513400 for idx=0<br />
qla2xxx [0000:37:00.1]-700e:5: qla2x00_start_sp failed = 11<br />
BUG: unable to handle kernel NULL pointer dereference at 0000000000000000<br />
PGD 0 P4D 0<br />
Oops: 0000 [#1] SMP NOPTI<br />
Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021<br />
Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc]<br />
RIP: 0010:__wake_up_common+0x4c/0x190<br />
RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086<br />
RAX: 0000000000000000 RBX: ffff8b08d3b26328 RCX: 0000000000000000<br />
RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffff8b08d3b26320<br />
RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffffffffffe8<br />
R10: 0000000000000000 R11: ffff95f3e0cb7a60 R12: ffff95f3e0cb7d20<br />
R13: 0000000000000003 R14: 0000000000000000 R15: 0000000000000000<br />
FS: 0000000000000000(0000) GS:ffff8b2fdf6c0000(0000) knlGS:0000000000000000<br />
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
CR2: 0000000000000000 CR3: 0000002f1e410002 CR4: 00000000007706e0<br />
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000<br />
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400<br />
PKRU: 55555554<br />
Call Trace:<br />
__wake_up_common_lock+0x7c/0xc0<br />
qla_nvme_ls_req+0x355/0x4c0 [qla2xxx]<br />
? __nvme_fc_send_ls_req+0x260/0x380 [nvme_fc]<br />
? nvme_fc_send_ls_req.constprop.42+0x1a/0x45 [nvme_fc]<br />
? nvme_fc_connect_ctrl_work.cold.63+0x1e3/0xa7d [nvme_fc]<br />
<br />
Remove unused nvme_ls_waitq wait queue. nvme_ls_waitq logic was removed<br />
previously in the commits tagged Fixed: below.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0b1ce92fabdb7d02ddf8641230a06e2752ae5baa
- https://git.kernel.org/stable/c/20fce500b232b970e40312a9c97e7f3b6d7a709c
- https://git.kernel.org/stable/c/522ee1b3030f3b6b5fd59489d12b4ca767c9e5da
- https://git.kernel.org/stable/c/92529387a0066754fd9cda080fb3298b8cca750c
- https://git.kernel.org/stable/c/b7084ebf4f54d46fed5153112d685f4137334175
- https://git.kernel.org/stable/c/f459d586fdf12c53116c9fddf43065165fdd5969