« Volver al listado

CVE-2023-54102

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow

A static code analysis tool flagged the possibility of buffer overflow when using copy_from_user() for a debugfs entry.

Currently, it is possible that copy_from_user() copies more bytes than what would fit in the mybuf char array. Add a min() restriction check between sizeof(mybuf) - 1 and nbytes passed from the userspace buffer to protect against buffer overflow.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54102",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "644a9d5e22761a41d5005a26996a643da96de962",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "e0e7faee3a7dd6f51350cda64997116a247eb045",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "f91037487036e2d2f18d3c2481be6b9a366bde7f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "a9df88cb31dcbd72104ec5883f35cbc1fb587e47",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "ad050f6cf681ebb850a9d4bc19474d3896476301",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6a828b0f6192b4930894925d1c1d0dc1f1d99e6e",
              "lessThan": "c6087b82a9146826564a55c5ca0164cac40348f5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/scsi/lpfc/lpfc_debugfs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.244",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.181",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.113",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.30",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.3.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.3.*"
            },
            {
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/lpfc/lpfc_debugfs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:12.093",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/644a9d5e22761a41d5005a26996a643da96de962",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a9df88cb31dcbd72104ec5883f35cbc1fb587e47",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ad050f6cf681ebb850a9d4bc19474d3896476301",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c6087b82a9146826564a55c5ca0164cac40348f5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0e7faee3a7dd6f51350cda64997116a247eb045",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f91037487036e2d2f18d3c2481be6b9a366bde7f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Prevent lpfc_debugfs_lockstat_write() buffer overflow\n\nA static code analysis tool flagged the possibility of buffer overflow when\nusing copy_from_user() for a debugfs entry.\n\nCurrently, it is possible that copy_from_user() copies more bytes than what\nwould fit in the mybuf char array.  Add a min() restriction check between\nsizeof(mybuf) - 1 and nbytes passed from the userspace buffer to protect\nagainst buffer overflow."
    }
  ],
  "lastModified": "2026-06-17T06:46:48.390",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}