CVE-2023-54179: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Array index may go out of bound Klocwork reports array 'vha->host_str' of size 16 may use index value(s) 16..19. Use snprintf() instead of sprintf().
Affected products
- Linux Linux: from 2.6.12, before 4.19.291 (fixed in 4.19.291); from 4.20, before 5.4.253 (fixed in 5.4.253); from 5.5, before 5.10.188 (fixed in 5.10.188); from 5.11, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.40 (fixed in 6.1.40); from 6.2, before 6.4.5 (fixed in 6.4.5)
Published 2025-12-30. Last modified 2026-06-17.