CVE-2023-54054
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54054 is a rejected/withdrawn CVE that was originally associated with a buffer overrun vulnerability in the Linux kernel's SCSI qla2xxx driver. The issue involved the driver using fc_els_flogi to calculate the size of a buffer, while the actual buffer nested inside fc_els_flogi was smaller, leading to an array index out-of-bounds condition (flagged by Klocwork static analysis). The CVE was formally rejected by its CVE Numbering Authority, and its status is listed as "Rejected" in the NVD (Feedly). The EPSS score is 0.00018, reflecting negligible exploitation probability (Feedly).

Technical details

The underlying defect — prior to CVE rejection — was classified as a buffer overflow / array index out-of-bounds issue (CWE-119/CWE-129) in the qla2xxx SCSI driver within the Linux kernel. The driver incorrectly used the fc_els_flogi structure to size a buffer, but the actual target buffer was a nested, smaller structure, creating a potential overrun condition. The fix involved replacing the structure name used in the size calculation to correctly reflect the nested buffer's dimensions (EUVD). Patches were backported to stable kernel branches including 5.10.188, 5.15.121, 6.1.40, 6.4.5, and 6.5 (Feedly).

Impact

Because CVE-2023-54054 has been formally rejected by its CVE Numbering Authority, no official impact assessment is associated with this identifier. The underlying kernel defect, if exploitable, could theoretically have led to memory corruption in the qla2xxx SCSI driver, potentially affecting system stability or integrity on Linux systems using Fibre Channel HBAs from QLogic. However, given the CVE's rejected status and the very low EPSS score (0.00018), no confirmed exploitation or real-world impact has been documented (Feedly).

Mitigation and workarounds

Since CVE-2023-54054 has been formally rejected, no official mitigation is required under this identifier. The underlying kernel code fix was nonetheless backported to Linux stable branches: 5.10.188, 5.15.121, 6.1.40, 6.4.5, and 6.5 (EUVD). Administrators running affected kernel versions with qla2xxx SCSI drivers should ensure their systems are updated to at least these patched versions as a general best practice.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management