SB20250916346 - Resource management error in Linux kernel scsi lpfc driver
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-53282)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the lpfc_wr_object() function in drivers/scsi/lpfc/lpfc_sli.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/21681b81b9ae548c5dae7ae00d931197a27f480c
- https://git.kernel.org/stable/c/51ab4eb1a25e73c7fc2ad9026520c4d8369c93cc
- https://git.kernel.org/stable/c/8becb97918f04bb177bc9c4e00c2bdb302e00944
- https://git.kernel.org/stable/c/8dfefa8f424ab208e552df1bfd008b732f3d0ad1
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.16