In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Remove unused nvmelswaitq wait queue
System crash when qla2x00startsp(sp) returns error code EGAIN and wakeup gets called for uninitialized wait queue sp->nvmels_waitq.
qla2xxx [0000:37:00.1]-2121:5: Returning existing qpair of ffff8ae2c0513400 for idx=0
qla2xxx [0000:37:00.1]-700e:5: qla2x00_start_sp failed = 11
BUG: unable to handle kernel NULL pointer dereference at 0000000000000000
PGD 0 P4D 0
Oops: 0000 [#1] SMP NOPTI
Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021
Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc]
RIP: 0010:__wake_up_common+0x4c/0x190
RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086
RAX: 0000000000000000 RBX: ffff8b08d3b26328 RCX: 0000000000000000
RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffff8b08d3b26320
RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffffffffffe8
R10: 0000000000000000 R11: ffff95f3e0cb7a60 R12: ffff95f3e0cb7d20
R13: 0000000000000003 R14: 0000000000000000 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff8b2fdf6c0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000002f1e410002 CR4: 00000000007706e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
PKRU: 55555554
Call Trace:
__wake_up_common_lock+0x7c/0xc0
qla_nvme_ls_req+0x355/0x4c0 [qla2xxx]
? __nvme_fc_send_ls_req+0x260/0x380 [nvme_fc]
? nvme_fc_send_ls_req.constprop.42+0x1a/0x45 [nvme_fc]
? nvme_fc_connect_ctrl_work.cold.63+0x1e3/0xa7d [nvme_fc]
Remove unused nvmelswaitq wait queue. nvmelswaitq logic was removed previously in the commits tagged Fixed: below.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7084ebf4f54d46fed5153112d685f4137334175",
"id": "CVE-2023-53280-03556754",
"digest": {
"function_hash": "280030158925814470270384560577044094358",
"length": 1450.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b1ce92fabdb7d02ddf8641230a06e2752ae5baa",
"id": "CVE-2023-53280-06657fb7",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105162227472190301434633228825483976851",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@20fce500b232b970e40312a9c97e7f3b6d7a709c",
"id": "CVE-2023-53280-095ce990",
"digest": {
"function_hash": "248147176363033433278629116484142234860",
"length": 1409.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f459d586fdf12c53116c9fddf43065165fdd5969",
"id": "CVE-2023-53280-108ae8fa",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105162227472190301434633228825483976851",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f459d586fdf12c53116c9fddf43065165fdd5969",
"id": "CVE-2023-53280-1563e7fc",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"331298699295315549929462383695540027158",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@92529387a0066754fd9cda080fb3298b8cca750c",
"id": "CVE-2023-53280-184d2e3b",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"331298699295315549929462383695540027158",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f459d586fdf12c53116c9fddf43065165fdd5969",
"id": "CVE-2023-53280-1d2fe016",
"digest": {
"function_hash": "27588653178011621933399444368730554735",
"length": 1427.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7084ebf4f54d46fed5153112d685f4137334175",
"id": "CVE-2023-53280-25f6a8a1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"241305226933158520366051164766979731692",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@92529387a0066754fd9cda080fb3298b8cca750c",
"id": "CVE-2023-53280-3c5391b5",
"digest": {
"function_hash": "248147176363033433278629116484142234860",
"length": 1409.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@20fce500b232b970e40312a9c97e7f3b6d7a709c",
"id": "CVE-2023-53280-4e67c887",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105162227472190301434633228825483976851",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@92529387a0066754fd9cda080fb3298b8cca750c",
"id": "CVE-2023-53280-55a4942a",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105162227472190301434633228825483976851",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@20fce500b232b970e40312a9c97e7f3b6d7a709c",
"id": "CVE-2023-53280-57a869ab",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"331298699295315549929462383695540027158",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b1ce92fabdb7d02ddf8641230a06e2752ae5baa",
"id": "CVE-2023-53280-755ed06f",
"digest": {
"function_hash": "101064099741966971102502015276353784805",
"length": 1408.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b1ce92fabdb7d02ddf8641230a06e2752ae5baa",
"id": "CVE-2023-53280-8451d4d6",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"331298699295315549929462383695540027158",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@92529387a0066754fd9cda080fb3298b8cca750c",
"id": "CVE-2023-53280-8ff48506",
"digest": {
"function_hash": "27588653178011621933399444368730554735",
"length": 1427.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7084ebf4f54d46fed5153112d685f4137334175",
"id": "CVE-2023-53280-9885b9d2",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"61313391676545451505116710618085146098",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@522ee1b3030f3b6b5fd59489d12b4ca767c9e5da",
"id": "CVE-2023-53280-ac84f530",
"digest": {
"function_hash": "27588653178011621933399444368730554735",
"length": 1427.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7084ebf4f54d46fed5153112d685f4137334175",
"id": "CVE-2023-53280-b9598d0e",
"digest": {
"function_hash": "276837192766393752350839507117566546948",
"length": 1224.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@522ee1b3030f3b6b5fd59489d12b4ca767c9e5da",
"id": "CVE-2023-53280-c64b775f",
"digest": {
"function_hash": "105407408804112034706685513128718178120",
"length": 1346.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@20fce500b232b970e40312a9c97e7f3b6d7a709c",
"id": "CVE-2023-53280-d36e081c",
"digest": {
"function_hash": "27588653178011621933399444368730554735",
"length": 1427.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@522ee1b3030f3b6b5fd59489d12b4ca767c9e5da",
"id": "CVE-2023-53280-d4122db8",
"digest": {
"threshold": 0.9,
"line_hashes": [
"17474884858139827165093379703611651841",
"259723016747466077793995259525514228024",
"235868330173122036910457182029663995893",
"8081374522548509023674818247331413788",
"138533957609552647593129401872986680001",
"293721240693887167301263741887565335453",
"85843046224181901737112286403064875675",
"331298699295315549929462383695540027158",
"274632364584034446220838370942665533464",
"66066048716157817870653148344450228220",
"224684155385628192978774644243564935184",
"317234799385057258708895525531267072386"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0b1ce92fabdb7d02ddf8641230a06e2752ae5baa",
"id": "CVE-2023-53280-d80b6a01",
"digest": {
"function_hash": "172445848582316441435819859340503466058",
"length": 1438.0
},
"target": {
"function": "qla_nvme_ls_req",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@522ee1b3030f3b6b5fd59489d12b4ca767c9e5da",
"id": "CVE-2023-53280-fa94483d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105162227472190301434633228825483976851",
"107721318436738435507458712947803722766",
"265216895777262647949096083544116350107",
"126579899997819998622056859134548480991"
]
},
"target": {
"file": "drivers/scsi/qla2xxx/qla_def.h"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f459d586fdf12c53116c9fddf43065165fdd5969",
"id": "CVE-2023-53280-fefbe860",
"digest": {
"function_hash": "105407408804112034706685513128718178120",
"length": 1346.0
},
"target": {
"function": "qla_nvme_post_cmd",
"file": "drivers/scsi/qla2xxx/qla_nvme.c"
},
"signature_type": "Function",
"signature_version": "v1"
}
]