CVE-2023-54011
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54011 is a vulnerability in the Linux kernel's scsi: mpi3mr driver, identified and resolved after detection by KASAN (Kernel Address Sanitizer). The flaw involves writing 64 bytes where only 32 bytes are correct, constituting an out-of-bounds write issue. It was published on December 24, 2025, and affects Linux kernel versions in the range introduced by commit 42fc9fee116fc6a225a1f738adf86689d5c39d49. No CVSS score has been assigned by NVD at this time, and the EPSS score is extremely low at 0.000170 (Feedly, EUVD).

Technical details

The root cause is an incorrect buffer write size in the mpi3mr SCSI driver within the Linux kernel — specifically, 64 bytes are written where only 32 bytes should be, which can result in a heap or stack out-of-bounds write (consistent with CWE-787: Out-of-bounds Write). The issue was surfaced by KASAN, a dynamic memory error detector built into the Linux kernel. Patches were applied across multiple stable branches, with fixes committed at abfe73c16b, ae7d45f5283d, and c8755f913a2f (kernel.org patch 1, kernel.org patch 2, kernel.org patch 3).

Impact

Exploitation of this vulnerability could lead to kernel memory corruption due to the oversized write in the mpi3mr SCSI driver. Depending on the memory layout at the time of the write, this could result in system instability, kernel panics (denial of service), or potentially privilege escalation if an attacker can control the conditions under which the driver operates. The impact is limited to systems using the mpi3mr driver (Broadcom MPI3 SAS/PCIe controller), reducing the affected asset scope (Feedly).

Mitigation and workarounds

Apply the upstream Linux kernel patches that correct the write size in the mpi3mr driver. Fixed commits are available for multiple stable branches: abfe73c16b (patch for 6.3+), c8755f913a2f (patch for 6.2.5+), and ae7d45f5283d (patch for 6.1.18+). Users should update to a patched kernel version as provided by their Linux distribution. Systems not using Broadcom MPI3-based SAS/PCIe controllers are not affected (kernel.org patch 1, kernel.org patch 2, kernel.org patch 3).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management