CVE-2023-53124
MEDIUMLinux Kernel 5.4.229-5.4.237 - NULL Pointer Dereference in mpt3sas_transport_port_add
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add() Port is allocated by sas_port_alloc_num() and rphy is allocated by either sas_end_device_alloc() or sas_expander_alloc(), all of which may return NULL. So we need to check the rphy to avoid possible NULL pointer access. If sas_rphy_add() returned with failure, rphy is set to NULL. We would access the rphy in the following lines which would also result NULL pointer access.
References (6)
Core 6
Core References
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
4.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (22)
Linux/Linux
< 6.2
Linux/Linux
5.10.163 - 5.10.176
Linux/Linux
5.10.176 - 5.10.*
Linux/Linux
5.15.104 - 5.15.*
Linux/Linux
5.15.86 - 5.15.104
Linux/Linux
5.4.229 - 5.4.238
Linux/Linux
5.4.238 - 5.4.*
Linux/Linux
6.0.16 - 6.1
Linux/Linux
6.1.2 - 6.1.21
Linux/Linux
6.1.21 - 6.1.*
... and 12 more
Published
May 02, 2025
Tracked Since
Feb 18, 2026