Linux Kernel SCSI lpfc Buffer Overflow Vulnerability in Debugfs

Vulnerability

A buffer overflow vulnerability has been identified in the Linux kernel's SCSI lpfc component. This issue arises in the debug filesystem (debugfs) when it receives malformed user input, leading to crashes. The vulnerability has been addressed by adjusting the input string lengths to ensure they fit within internal buffers, while also leaving space for NULL terminators.

Impact

Exploitation of this vulnerability can lead to buffer overflow crashes, causing a denial of service by disrupting normal system operations.

Added: Jun 18, 2025, 7:39 PM
Updated: Jun 18, 2025, 7:39 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.