CVE-2023-53124

MEDIUM

Linux Kernel 5.4.229-5.4.237 - NULL Pointer Dereference in mpt3sas_transport_port_add

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix NULL pointer access in mpt3sas_transport_port_add() Port is allocated by sas_port_alloc_num() and rphy is allocated by either sas_end_device_alloc() or sas_expander_alloc(), all of which may return NULL. So we need to check the rphy to avoid possible NULL pointer access. If sas_rphy_add() returned with failure, rphy is set to NULL. We would access the rphy in the following lines which would also result NULL pointer access.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (22)
Linux/Linux < 6.2
Linux/Linux 5.10.163 - 5.10.176
Linux/Linux 5.10.176 - 5.10.*
Linux/Linux 5.15.104 - 5.15.*
Linux/Linux 5.15.86 - 5.15.104
Linux/Linux 5.4.229 - 5.4.238
Linux/Linux 5.4.238 - 5.4.*
Linux/Linux 6.0.16 - 6.1
Linux/Linux 6.1.2 - 6.1.21
Linux/Linux 6.1.21 - 6.1.*
... and 12 more
Published May 02, 2025
Tracked Since Feb 18, 2026