cbcvebase.
CVE-2023-53508
published 2025-10-01

CVE-2023-53508: In the Linux kernel, the following vulnerability has been resolved: ublk: fail to start device if queue setup is interrupted In ublk_ctrl_start_dev(), if…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ublk: fail to start device if queue setup is interrupted In ublk_ctrl_start_dev(), if wait_for_completion_interruptible() is interrupted by signal, queues aren't setup successfully yet, so we have to fail UBLK_CMD_START_DEV, otherwise kernel oops can be triggered. Reported by German when working on qemu-storage-deamon which requires single thread ublk daemon.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 71f28f3136aff5890cd56de78abc673f8393cad9 < 0d5916c439574b18a0734872daa0022b3d6105ad0d5916c439574b18a0734872daa0022b3d6105ad
linuxlinux>= 71f28f3136aff5890cd56de78abc673f8393cad9 < 6ab3e7d424cd413d7a5e976c8a30b4ffa84a65dd6ab3e7d424cd413d7a5e976c8a30b4ffa84a65dd
linuxlinux>= 71f28f3136aff5890cd56de78abc673f8393cad9 < 53e7d08f6d6e214c40db1f51291bb2975c789dc253e7d08f6d6e214c40db1f51291bb2975c789dc2
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 6.0 < 6.1.436.1.43
linuxlinux_kernel>= 6.2 < 6.4.86.4.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.