CVE-2023-53118
published 2025-05-02CVE-2023-53118: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a procfs host directory removal regression scsi_proc_hostdir_rm() decreases…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fix a procfs host directory removal regression
scsi_proc_hostdir_rm() decreases a reference counter and hence must only be
called once per host that is removed. This change does not require a
scsi_add_host_with_dma() change since scsi_add_host_with_dma() will return
0 (success) if scsi_proc_host_add() is called.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 17e98a5ede81b7696bec421f7afa2dfe467f5e6b < 7e0ae8667fcdd99d1756922e1140cac75f5fa279 | 7e0ae8667fcdd99d1756922e1140cac75f5fa279 |
| linux | linux | >= 1ec363599f8346d5a8d08c71a0d9860d6c420ec0 < 73f030d4ef6d1ad17f824a0a2eb637ef7a9c7d51 | 73f030d4ef6d1ad17f824a0a2eb637ef7a9c7d51 |
| linux | linux | >= 4.19.278 < 4.20 | 4.20 |
| linux | linux | >= 5.10.175 < 5.10.176 | 5.10.176 |
| linux | linux | >= 5.15.103 < 5.15.104 | 5.15.104 |
| linux | linux | >= 5.4.237 < 5.4.238 | 5.4.238 |
| linux | linux | >= 6.1.20 < 6.1.21 | 6.1.21 |
| linux | linux | >= 6.2.7 < 6.2.8 | 6.2.8 |
| linux | linux | >= 6b223e32d66ca9db1f252f433514783d8b22a8e1 < 68c665bb185037e7eb66fb792c61da9d7151e99c | 68c665bb185037e7eb66fb792c61da9d7151e99c |
| linux | linux | >= 891a3cba425cf483d96facca55aebd6ff1da4338 < 88c3d3bb6469cea929ac68fd326bdcbefcdfdd83 | 88c3d3bb6469cea929ac68fd326bdcbefcdfdd83 |
| linux | linux | >= e471e928de97b00f297ad1015cc14f9459765713 < 2a764d55e938743efa7c2cba7305633bcf227f09 | 2a764d55e938743efa7c2cba7305633bcf227f09 |
| linux | linux | >= fc663711b94468f4e1427ebe289c9f05669699c9 < be03df3d4bfe7e8866d4aa43d62e648ffe884f5f | be03df3d4bfe7e8866d4aa43d62e648ffe884f5f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 4.19.278 < 4.20 | 4.20 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwj4-hj56-h864: In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fix a procfs host directory removal regression
scsi_proc_hostdir_rm(
ghsa_unreviewed·2025-05-02
CVE-2023-53118 [MEDIUM] GHSA-fwj4-hj56-h864: In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fix a procfs host directory removal regression
scsi_proc_hostdir_rm(
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fix a procfs host directory removal regression
scsi_proc_hostdir_rm() decreases a reference counter and hence must only be
called once per host that is removed. This change does not require a
scsi_add_host_with_dma() change since scsi_add_host_with_dma() will return
0 (success) if scsi_proc_host_add() is called.
OSV
CVE-2023-53118: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a procfs host directory removal regression scsi_proc_hostdir_rm()
osv·2025-05-02·CVSS 5.5
CVE-2023-53118 [MEDIUM] CVE-2023-53118: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a procfs host directory removal regression scsi_proc_hostdir_rm()
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a procfs host directory removal regression scsi_proc_hostdir_rm() decreases a reference counter and hence must only be called once per host that is removed. This change does not require a scsi_add_host_with_dma() change since scsi_add_host_with_dma() will return 0 (success) if scsi_proc_host_add() is called.
Red Hat
kernel: scsi: core: Fix a procfs host directory removal regression
vendor_redhat·2025-05-02·CVSS 5.5
CVE-2023-53118 [MEDIUM] kernel: scsi: core: Fix a procfs host directory removal regression
kernel: scsi: core: Fix a procfs host directory removal regression
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Fix a procfs host directory removal regression
scsi_proc_hostdir_rm() decreases a reference counter and hence must only be
called once per host that is removed. This change does not require a
scsi_add_host_with_dma() change since scsi_add_host_with_dma() will return
0 (success) if scsi_proc_host_add() is called.
Statement: Fixes a regression where scsi_proc_hostdir_rm() could be called multiple times, incorrectly decreasing a reference counter during SCSI host removal. Triggered only in specific device teardown sequences. Requires elevated privileges and precise timing. Not exploitable by unprivileged users. No confidentiality or integrity imp
Debian
CVE-2023-53118: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: core:...
vendor_debian·2023·CVSS 5.5
CVE-2023-53118 [MEDIUM] CVE-2023-53118: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: core:...
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a procfs host directory removal regression scsi_proc_hostdir_rm() decreases a reference counter and hence must only be called once per host that is removed. This change does not require a scsi_add_host_with_dma() change since scsi_add_host_with_dma() will return 0 (success) if scsi_proc_host_add() is called.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2a764d55e938743efa7c2cba7305633bcf227f09https://git.kernel.org/stable/c/68c665bb185037e7eb66fb792c61da9d7151e99chttps://git.kernel.org/stable/c/73f030d4ef6d1ad17f824a0a2eb637ef7a9c7d51https://git.kernel.org/stable/c/7e0ae8667fcdd99d1756922e1140cac75f5fa279https://git.kernel.org/stable/c/88c3d3bb6469cea929ac68fd326bdcbefcdfdd83https://git.kernel.org/stable/c/be03df3d4bfe7e8866d4aa43d62e648ffe884f5f
2025-05-02
Published