CVE-2023-54289
Published: December 31, 2025Last modified: December 31, 2025
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Fix NULL dereference in error handling Smatch reported: drivers/scsi/qedf/qedf_main.c:3056 qedf_alloc_global_queues() warn: missing unwind goto? At this point in the function, nothing has been allocated so we can return directly. In particular the "qedf->global_queues" have not been allocated so calling qedf_free_global_queues() will lead to a NULL dereference when we check if (!gl[i]) and "gl" is NULL.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.42-r0) |
| 25 LTS | linux-lts | Not affected (6.6.89-r0) | |
| Stream | linux-lts | Fixed (6.6.58-r0) |
References
- https://git.kernel.org/stable/c/08c001c1e9444a3046c79a99aa93ac48073b18cc
- https://git.kernel.org/stable/c/271c9b2eb60149afbeab28cb39e52f73bde9900c
- https://git.kernel.org/stable/c/961c8370c5f7e80a267680476e1bcff34bffe71a
- https://git.kernel.org/stable/c/ac64019e4d4b08c23edb117e0b2590985e33de1d
- https://git.kernel.org/stable/c/b1de5105d29b145b727b797e2d5de071ab3a7ca1
- https://git.kernel.org/stable/c/c316bde418af4c2a9df51149ed01d1bd8ca5bebf
- https://git.kernel.org/stable/c/f025312b089474a54e4859f3453771314d9e3d4f