CVE-2023-54179

Linux Kernel - Buffer Overflow in SCSI qla2xxx Host String Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of size 16 may use index value(s) 16..19. Use snprintf() instead of sprintf().

Scores

EPSS 0.0018
EPSS Percentile 7.7%

Details

Status published
Products (22)
linux/Kernel 2.6.12 - 4.19.291linux
linux/Kernel 4.20.0 - 5.4.253linux
linux/Kernel 5.11.0 - 5.15.121linux
linux/Kernel 5.16.0 - 6.1.40linux
linux/Kernel 5.5.0 - 5.10.188linux
linux/Kernel 6.2.0 - 6.4.5linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 2b3bdef089b920b4a19fefb4f4e6dda56a4bb583
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 748d8f8698a2f48ffe32dd7b35dbab1810ed1f82
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - bcd773969a87d9802053c0db5be84abd6594a024
... and 12 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026