CVE-2023-53066
MEDIUMLinux Kernel 4.7-4.14.311 - NULL Pointer Dereference in qed_iov_get_vf_info
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info We have to make sure that the info returned by the helper is valid before using it. Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.
References (8)
Core 8
Core References
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
7.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (20)
Linux/Linux
< 4.7
Linux/Linux
4.14.312 - 4.14.*
Linux/Linux
4.19.280 - 4.19.*
Linux/Linux
4.7
Linux/Linux
5.10.177 - 5.10.*
Linux/Linux
5.15.105 - 5.15.*
Linux/Linux
5.4.240 - 5.4.*
Linux/Linux
6.1.22 - 6.1.*
Linux/Linux
6.2.9 - 6.2.*
Linux/Linux
6.3
... and 10 more
Published
May 02, 2025
Tracked Since
Feb 18, 2026