CVE-2023-54108: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests The following message and call trace was seen with debug kernels: DMA-API: qla2xxx 0000:41:00.0: device driver failed to check map error [device address=0x00000002a3ff38d8] [size=1024 bytes] [mapped as single] WARNING: CPU: 0 PID: 2930 at kernel/dma/debug.c:1017 check_unmap+0xf42/0x1990 Call Trace: debug_dma_unmap_page+0xc9/0x100 qla_nvme_ls_unmap+0x141/0x210 [qla2xxx] Remove DMA mapping from the driver altogether, as it is already done by FC layer. This prevents the warning.

Affected products

  • Linux Linux: from 5.4.189, before 5.4.235 (fixed in 5.4.235); from 5.10.110, before 5.10.173 (fixed in 5.10.173); from 5.15.33, before 5.15.99 (fixed in 5.15.99); from 5.16.19, before 5.17 (fixed in 5.17); from 5.17.2, before 5.18 (fixed in 5.18); from 5.18, before 6.1.16 (fixed in 6.1.16); …

Published 2025-12-24. Last modified 2026-06-17.