CVE-2023-53387Expired Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix device management cmd timeout flow In the UFS error handling flow, the host will send a device management cmd (NOP OUT) to the device for link recovery. If this cmd times out and clearing the doorbell fails, ufshcd_wait_for_dev_cmd() will do nothing and return. hba->dev_cmd.complete struct is not set to NULL. When this happens, if cmd has been completed by device, then we will call complete() in __ufshcd_

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel6.26.2.3+1
Debianlinux/linux_kernel< 6.1.20-1+2
CVEListV5linux/linuxf5c2976e0cb0f6236013bfb479868531b04f61d4cf45493432704786a0f8294c7723ad4eeb5fff24+4
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53387: In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix device management cmd timeout flow In the UFS error handling2025-09-18
GHSA
GHSA-w6pv-gx3q-3r57: In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix device management cmd timeout flow In the UFS error handlin2025-09-18

📋Vendor Advisories

3
Red Hat
kernel: Linux kernel: Denial of Service in UFS subsystem2025-09-18
Microsoft
scsi: ufs: core: Fix device management cmd timeout flow2025-09-09
Debian
CVE-2023-53387: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ...2023

💬Community

1
Bugzilla
CVE-2023-53387 kernel: Linux kernel: Denial of Service in UFS subsystem2025-09-18
CVE-2023-53387 — Expired Pointer Dereference in Linux | cvebase