cbcvebase.
CVE-2023-53041
published 2025-05-02

CVE-2023-53041: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Perform lockless command completion in abort path While adding and removing…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Perform lockless command completion in abort path While adding and removing the controller, the following call trace was observed: WARNING: CPU: 3 PID: 623596 at kernel/dma/mapping.c:532 dma_free_attrs+0x33/0x50 CPU: 3 PID: 623596 Comm: sh Kdump: loaded Not tainted 5.14.0-96.el9.x86_64 #1 RIP: 0010:dma_free_attrs+0x33/0x50 Call Trace: qla2x00_async_sns_sp_done+0x107/0x1b0 [qla2xxx] qla2x00_abort_srb+0x8e/0x250 [qla2xxx] ? ql_dbg+0x70/0x100 [qla2xxx] __qla2x00_abort_all_cmds+0x108/0x190 [qla2xxx] qla2x00_abort_all_cmds+0x24/0x70 [qla2xxx] qla2x00_abort_isp_cleanup+0x305/0x3e0 [qla2xxx] qla2x00_remove_one+0x364/0x400 [qla2xxx] pci_device_remove+0x36/0xa0 __device_release_driver+0x17a/0x230 device_release_driver+0x24/0x30 pci_stop_bus_device+0x68/0x90 pci_stop_and_remove_bus_device_locked+0x16/0x30 remove_store+0x75/0x90 kernfs_fop_write_iter+0x11c/0x1b0 new_sync_write+0x11f/0x1b0 vfs_write+0x1eb/0x280 ksys_write+0x5f/0xe0 do_syscall_64+0x5c/0x80 ? do_user_addr_fault+0x1d8/0x680 ? do_syscall_64+0x69/0x80 ? exc_page_fault+0x62/0x140 ? asm_exc_page_fault+0x8/0x30 entry_SYSCALL_64_after_hwframe+0x44/0xae The command was completed in the abort path during driver unload with a lock held, causing the warning in abort path. Hence complete the command without any lock held.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 31c1f455203e56a3ce8d5dd92f37c83d07bd5bd5 < 9189f20b4c5307c0998682bb522e481b4567a8b89189f20b4c5307c0998682bb522e481b4567a8b8
linuxlinux>= 5.3.17 < 5.45.4
linuxlinux>= 5.4.4 < 5.4.2405.4.240
linuxlinux>= f45bca8c5052e8c59bab64ee90c44441678b9a52 < 231cfa78ec5badd84a1a2b09465bfad1a926aba1231cfa78ec5badd84a1a2b09465bfad1a926aba1
linuxlinux>= f45bca8c5052e8c59bab64ee90c44441678b9a52 < d6f7377528d2abf338e504126e44439541be8f7dd6f7377528d2abf338e504126e44439541be8f7d
linuxlinux>= f45bca8c5052e8c59bab64ee90c44441678b9a52 < cd0a1804ac5bab2545ac700c8d0fe9ae9284c567cd0a1804ac5bab2545ac700c8d0fe9ae9284c567
linuxlinux>= f45bca8c5052e8c59bab64ee90c44441678b9a52 < 415d614344a4f1bbddf55d724fc7eb9ef4b39aad415d614344a4f1bbddf55d724fc7eb9ef4b39aad
linuxlinux>= f45bca8c5052e8c59bab64ee90c44441678b9a52 < 0367076b0817d5c75dfb83001ce7ce5c64d803a90367076b0817d5c75dfb83001ce7ce5c64d803a9
linuxlinux_kernel< 5.4.2405.4.240
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.11 < 5.15.1055.15.105
linuxlinux_kernel>= 5.16 < 6.1.226.1.22
linuxlinux_kernel>= 5.5 < 5.10.1775.10.177
linuxlinux_kernel>= 6.2 < 6.2.96.2.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.