CVE-2023-54054

Source
https://cve.org/CVERecord?id=CVE-2023-54054
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54054.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-54054
Downstream
Published
2025-12-24T12:23:03.196Z
Modified
2026-04-10T05:07:03.248493Z
Summary
scsi: qla2xxx: Fix buffer overrun
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix buffer overrun

Klocwork warning: Buffer Overflow - Array Index Out of Bounds

Driver uses fcelsflogi to calculate size of buffer. The actual buffer is nested inside of fcelsflogi which is smaller.

Replace structure name to allow proper size calculation.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54054.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
eecb8a491c824a9376155d26ec95b6d0054c059c
Fixed
89250e775dcc4482d8e970ed92ad2c9458b14a8a
Fixed
2dddbf8de128289a3fb7ae38d9bc4b2217205ec1
Fixed
d5e7c9cd56e987c8687859a0bf38fd86aa8f3cec
Fixed
b68710a8094fdffe8dd4f7a82c82649f479bb453

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54054.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.188
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.121
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.40
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.4.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54054.json"