CVE-2023-52508

Source
https://cve.org/CVERecord?id=CVE-2023-52508
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-52508.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-52508
Downstream
Related
Published
2024-03-02T21:52:21.361Z
Modified
2026-03-23T05:03:21.429205047Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid()
Details

In the Linux kernel, the following vulnerability has been resolved:

nvme-fc: Prevent null pointer dereference in nvmefcio_getuuid()

The nvmefcfcpop structure describing an AEN operation is initialized with a null request structure pointer. An FC LLDD may make a call to nvmefciogetuuid passing a pointer to an nvmefcfcpreq for an AEN operation.

Add validation of the request structure pointer before dereference.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52508.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
827fc630e4c8087df5a8e8ee013b686bd6f13736
Fixed
be90c9e29dd59b7d19a73297a1590ff3ec1d22ea
Fixed
dd46b3ac7322baf3772b33b29726e94f98289db7
Fixed
8ae5b3a685dc59a8cf7ccfe0e850999ba9727a3c
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
7a41fdf27a4b1ee565ce5bf3e409b2df0b8514c4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-52508.json"