cbcvebase.
CVE-2023-53140
published 2025-05-02

CVE-2023-53140: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier Remove the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.3th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier Remove the /proc/scsi/${proc_name} directory earlier to fix a race condition between unloading and reloading kernel modules. This fixes a bug introduced in 2009 by commit 77c019768f06 ("[SCSI] fix /proc memory leak in the SCSI core"). Fix the following kernel warning: proc_dir_entry 'scsi/scsi_debug' already registered WARNING: CPU: 19 PID: 27986 at fs/proc/generic.c:376 proc_register+0x27d/0x2e0 Call Trace: proc_mkdir+0xb5/0xe0 scsi_proc_hostdir_add+0xb5/0x170 scsi_host_alloc+0x683/0x6c0 sdebug_driver_probe+0x6b/0x2d0 [scsi_debug] really_probe+0x159/0x540 __driver_probe_device+0xdc/0x230 driver_probe_device+0x4f/0x120 __device_attach_driver+0xef/0x180 bus_for_each_drv+0xe5/0x130 __device_attach+0x127/0x290 device_initial_probe+0x17/0x20 bus_probe_device+0x110/0x130 device_add+0x673/0xc80 device_register+0x1e/0x30 sdebug_add_host_helper+0x1a7/0x3b0 [scsi_debug] scsi_debug_init+0x64f/0x1000 [scsi_debug] do_one_initcall+0xd7/0x470 do_init_module+0xe7/0x330 load_module+0x122a/0x12c0 __do_sys_finit_module+0x124/0x1a0 __x64_sys_finit_module+0x46/0x50 do_syscall_64+0x38/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < 13daafe1e209b03e9bda16ff2bd2b2da145a139b13daafe1e209b03e9bda16ff2bd2b2da145a139b
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < 891a3cba425cf483d96facca55aebd6ff1da4338891a3cba425cf483d96facca55aebd6ff1da4338
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < 6b223e32d66ca9db1f252f433514783d8b22a8e16b223e32d66ca9db1f252f433514783d8b22a8e1
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < e471e928de97b00f297ad1015cc14f9459765713e471e928de97b00f297ad1015cc14f9459765713
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < 17e98a5ede81b7696bec421f7afa2dfe467f5e6b17e98a5ede81b7696bec421f7afa2dfe467f5e6b
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < 1ec363599f8346d5a8d08c71a0d9860d6c420ec01ec363599f8346d5a8d08c71a0d9860d6c420ec0
linuxlinux>= 77c019768f0607c36e25bec11ce3e1eabef09277 < fc663711b94468f4e1427ebe289c9f05669699c9fc663711b94468f4e1427ebe289c9f05669699c9
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 2.6.30 < 4.19.2784.19.278
linuxlinux_kernel>= 4.20 < 5.4.2375.4.237
linuxlinux_kernel>= 5.11 < 5.15.1035.15.103
linuxlinux_kernel>= 5.16 < 6.1.206.1.20
linuxlinux_kernel>= 5.5 < 5.10.1755.10.175
linuxlinux_kernel>= 6.2 < 6.2.76.2.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.