CVE-2023-52809 affects the Linux kernel SCSI libfc component: fc_lport_ptp_setup() failed to verify whether fc_rport_create() returned NULL. A local attacker able to reach the affected Fibre Channel code path could trigger a NULL-pointer dereference, crashing the host and causing denial of service. Red Hat rates the flaw Low severity with a CVSS v3.1 score of 4.4, while NVD assigns 5.5; both identify high availability impact.
Linux stable kernels have been fixed across supported branches, and the kernel CVE team advises updating to the latest stable release rather than cherry-picking the patch. Red Hat issued fixes for RHEL 8 and multiple RHEL 9 streams, including RHEL 9 and 9.2 EUS; kernel-rt packages for RHEL 8 and RHEL 9 remained affected at publication. RHEL 6 and RHEL 7 kernel packages are outside support scope and should be treated as affected.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5066 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:5067 for its kernel-rt package, addressing CVE-2023-52809.
Red Hat released RHSA-2024:4928 to address CVE-2023-52809 in the Red Hat Enterprise Linux 9 kernel.
The Linux kernel CVE team announced CVE-2023-52809, a SCSI libfc flaw in which fc_lport_ptp_setup() failed to validate a NULL return from fc_rport_create(), potentially causing a kernel NULL-pointer dereference. Stable-kernel fixes were made available across versions 4.14.331 through 6.7.
Red Hat released RHSA-2024:7000 to fix CVE-2023-52809 in the Red Hat Enterprise Linux 8 kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.