In the Linux kernel, the following vulnerability has been resolved:
qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
We have to make sure that the info returned by the helper is valid
before using it.
Found by Linux Verification Center (linuxtesting.org) with the SVACE
static analysis tool.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Jun 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
Weaknesses | CWE-476 | |
CPEs | cpe:/a:redhat:enterprise_linux:9 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
Mon, 05 May 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 02 May 2025 16:00:00 +0000

Status: PUBLISHED
Assigner: Linux
Published: 2025-05-02T15:55:19.730Z
Updated: 2025-05-04T07:49:04.496Z
Reserved: 2025-05-02T15:51:43.548Z
Link: CVE-2023-53066

No data.

Status : Awaiting Analysis
Published: 2025-05-02T16:15:25.673
Modified: 2025-05-05T20:54:45.973
Link: CVE-2023-53066
