CVE-2023-53431Improper Validation of Specified Index, Position, or Offset in Input in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Handle enclosure with just a primary component gracefully This reverts commit 3fe97ff3d949 ("scsi: ses: Don't attach if enclosure has no components") and introduces proper handling of case where there are no detected secondary components, but primary component (enumerated in num_enclosures) does exist. That fix was originally proposed by Ding Hui . Completely ignoring devices that have one primary enclosure and no

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel2.6.254.19.281+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux9927c68864e9c39cc317b4f559309ba29e6421684e7c498c3713b09bef20c76c7319555637e8bbd5+7
debiandebian/linux< linux 6.1.25-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-36rm-q238-p59m: In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Don't attach if enclosure has no components An enclosure with no comp2025-09-18
OSV
CVE-2023-53431: In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Handle enclosure with just a primary component gracefully This reverts2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service in scsi_ses due to enclosure with no components2025-09-18
Debian
CVE-2023-53431: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: ses: ...2023

💬Community

1
Bugzilla
CVE-2023-53431 kernel: Linux kernel: Denial of Service in scsi_ses due to enclosure with no components2025-09-18
CVE-2023-53431 — Linux vulnerability | cvebase