cbcvebase.
CVE-2023-53464
published 2025-10-01

CVE-2023-53464: In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param() The validity of sock…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param() The validity of sock should be checked before assignment to avoid incorrect values. Commit 57569c37f0ad ("scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername()") introduced this change which may lead to inconsistent values of tcp_sw_conn->sendpage and conn->datadgst_en. Fix the issue by moving the position of the assignment.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.150 < 5.10.1785.10.178
linuxlinux>= 5.15.75 < 5.15.1075.15.107
linuxlinux>= 5.19.17 < 5.205.20
linuxlinux>= 57569c37f0add1b6489e1a1563c71519daf732cf < 6e06a68fbbfcd8576eee8f7139fa2b13c9b72e916e06a68fbbfcd8576eee8f7139fa2b13c9b72e91
linuxlinux>= 57569c37f0add1b6489e1a1563c71519daf732cf < b287e21e73ec23f3788fbe40037c42dbe6e9a9a9b287e21e73ec23f3788fbe40037c42dbe6e9a9a9
linuxlinux>= 57569c37f0add1b6489e1a1563c71519daf732cf < 48b19b79cfa37b1e50da3b5a8af529f994c0890148b19b79cfa37b1e50da3b5a8af529f994c08901
linuxlinux>= 6.0.3 < 6.16.1
linuxlinux>= 884a788f065578bb640382279a83d1df433b13e6 < 499757ad3332e2527254f9ab68dec1da087b1d96499757ad3332e2527254f9ab68dec1da087b1d96
linuxlinux>= a26b0658751bb0a3b28386fca715333b104d32a2 < 5e5c5f472972c4bc9430adc08b36763a0fa5b9f75e5c5f472972c4bc9430adc08b36763a0fa5b9f7
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.10.150 < 5.10.1785.10.178
linuxlinux_kernel>= 5.15.75 < 5.15.1075.15.107
linuxlinux_kernel>= 5.19.17 < 6.06.0
linuxlinux_kernel>= 6.0.3 < 6.1.246.1.24
linuxlinux_kernel>= 6.2 < 6.2.116.2.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.