CVE-2023-54102

high

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow A static code analysis tool flagged the possibility of buffer overflow when using copy_from_user() for a debugfs entry. Currently, it is possible that copy_from_user() copies more bytes than what would fit in the mybuf char array. Add a min() restriction check between sizeof(mybuf) - 1 and nbytes passed from the userspace buffer to protect against buffer overflow.

References

https://git.kernel.org/stable/c/f91037487036e2d2f18d3c2481be6b9a366bde7f

https://git.kernel.org/stable/c/e0e7faee3a7dd6f51350cda64997116a247eb045

https://git.kernel.org/stable/c/c6087b82a9146826564a55c5ca0164cac40348f5

https://git.kernel.org/stable/c/ad050f6cf681ebb850a9d4bc19474d3896476301

https://git.kernel.org/stable/c/a9df88cb31dcbd72104ec5883f35cbc1fb587e47

https://git.kernel.org/stable/c/644a9d5e22761a41d5005a26996a643da96de962

Details

Source: Mitre, NVD

Published: 2025-12-24

Updated: 2025-12-24

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0003