CVE-2023-54289

medium

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Fix NULL dereference in error handling Smatch reported: drivers/scsi/qedf/qedf_main.c:3056 qedf_alloc_global_queues() warn: missing unwind goto? At this point in the function, nothing has been allocated so we can return directly. In particular the "qedf->global_queues" have not been allocated so calling qedf_free_global_queues() will lead to a NULL dereference when we check if (!gl[i]) and "gl" is NULL.

References

https://git.kernel.org/stable/c/f025312b089474a54e4859f3453771314d9e3d4f

https://git.kernel.org/stable/c/c316bde418af4c2a9df51149ed01d1bd8ca5bebf

https://git.kernel.org/stable/c/b1de5105d29b145b727b797e2d5de071ab3a7ca1

https://git.kernel.org/stable/c/ac64019e4d4b08c23edb117e0b2590985e33de1d

https://git.kernel.org/stable/c/961c8370c5f7e80a267680476e1bcff34bffe71a

https://git.kernel.org/stable/c/271c9b2eb60149afbeab28cb39e52f73bde9900c

https://git.kernel.org/stable/c/08c001c1e9444a3046c79a99aa93ac48073b18cc

Details

Source: Mitre, NVD

Published: 2025-12-30

Updated: 2025-12-31

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024