scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup()
Published May 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
fc_lport_ptp_setup() did not check the return value of fc_rport_create() which can return NULL and would cause a NULL pointer dereference. Address this issue by checking return value of fc_rport_create() and log error message on fc_rport_create() failed.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.29StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.29
- Version 4.14.331StatusunaffectedConstraints<=4.14.*
- Version 4.19.300StatusunaffectedConstraints<=4.19.*
- Version 5.10.202StatusunaffectedConstraints<=5.10.*
- Version 5.15.140StatusunaffectedConstraints<=5.15.*
- Version 5.4.262StatusunaffectedConstraints<=5.4.*
- Version 6.1.64StatusunaffectedConstraints<=6.1.*
- Version 6.5.13StatusunaffectedConstraints<=6.5.*
- Version 6.6.3StatusunaffectedConstraints<=6.6.*
- Version 6.7StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.14.331
- ≥ 4.15 · < 4.19.300
- ≥ 4.20 · < 5.4.262
- ≥ 5.5 · < 5.10.202
- ≥ 5.11 · < 5.15.140
- ≥ 5.16 · < 6.1.64
- ≥ 6.2 · < 6.5.13
- ≥ 6.6 · < 6.6.3
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.28.1.el9_4
Fixed · RHSA-2024:4928
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.28.1.el9_4
Fixed · RHSA-2024:4928
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.77.1.el9_2
Fixed · RHSA-2024:5066
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2
Fixed · RHSA-2024:5067
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.28.1.el9_4 | Fixed | RHSA-2024:4928 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.28.1.el9_4 | Fixed | RHSA-2024:4928 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.77.1.el9_2 | Fixed | RHSA-2024:5066 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.77.1.rt14.362.el9_2 | Fixed | RHSA-2024:5067 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-52809 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282669 Issue Tracking
- https://git.kernel.org/stable/c/442fd24d7b6b29e4a9cd9225afba4142d5f522ba Patch
- https://git.kernel.org/stable/c/4df105f0ce9f6f30cda4e99f577150d23f0c9c5f Patch
- https://git.kernel.org/stable/c/56d78b5495ebecbb9395101f3be177cd0a52450b Patch
- https://git.kernel.org/stable/c/6b9ecf4e1032e645873933e5b43cbb84cac19106 Patch
- https://git.kernel.org/stable/c/77072ec41d6ab3718c3fc639bc149b8037caedfa Patch
- https://git.kernel.org/stable/c/930f0aaba4820d6362de4e6ed569eaf444f1ea4e Patch
- https://git.kernel.org/stable/c/b549acf999824d4f751ca57965700372f2f3ad00 Patch
- https://git.kernel.org/stable/c/bb83f79f90e92f46466adcfd4fd264a7ae0f0f01 Patch
- https://git.kernel.org/stable/c/f6fe7261b92b21109678747f36df9fdab1e30c34 Patch
- https://lore.kernel.org/linux-cve-announce/2024052102-CVE-2023-52809-f07c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52809
- https://www.cve.org/CVERecord?id=CVE-2023-52809
Change history (0)
No recorded changes yet.