CVE-2023-52508

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
02/03/2024
Last modified:
19/03/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()<br /> <br /> The nvme_fc_fcp_op structure describing an AEN operation is initialized with a<br /> null request structure pointer. An FC LLDD may make a call to<br /> nvme_fc_io_getuuid passing a pointer to an nvmefc_fcp_req for an AEN operation.<br /> <br /> Add validation of the request structure pointer before dereference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.56 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.5.6 (excluding)
cpe:2.3:o:linux:linux_kernel:6.6:rc1:*:*:*:*:*:*