CVE-2023-53456
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/10/2025
Last modified:
16/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: qla4xxx: Add length check when parsing nlattrs<br />
<br />
There are three places that qla4xxx parses nlattrs:<br />
<br />
- qla4xxx_set_chap_entry()<br />
<br />
- qla4xxx_iface_set_param()<br />
<br />
- qla4xxx_sysfs_ddb_set_param()<br />
<br />
and each of them directly converts the nlattr to specific pointer of<br />
structure without length checking. This could be dangerous as those<br />
attributes are not validated and a malformed nlattr (e.g., length 0) could<br />
result in an OOB read that leaks heap dirty data.<br />
<br />
Add the nla_len check before accessing the nlattr data and return EINVAL if<br />
the length check fails.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.2 (including) | 4.14.326 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 4.19.295 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.257 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.195 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.132 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.53 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.4.16 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.5 (including) | 6.5.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/25feffb3fbd51ae81d92c65cebc0e932663828b3
- https://git.kernel.org/stable/c/47cd3770e31df942e2bb925a9a855c79ed0662eb
- https://git.kernel.org/stable/c/47f3be62eab50b8cd7e1ae5fc2c4dae687497c34
- https://git.kernel.org/stable/c/4ed21975311247bb84e82298eeb359ec0a0fa84d
- https://git.kernel.org/stable/c/5925e224cc6edfef57b20447f18323208461309b
- https://git.kernel.org/stable/c/6d65079c69dc1feb817ed71f5bd15e83a7d6832d
- https://git.kernel.org/stable/c/b018c0440b871d8b001c996e95fa4538bd292de6
- https://git.kernel.org/stable/c/cfa6a1a79ed6d336fac7a5d87eb5471e4401829f
- https://git.kernel.org/stable/c/f61fc650c47849637fa1771a31a11674c824138a



