CVE-2023-53521Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read5 documents5 sources
Severity
7.1HIGHNVD
EPSS
0.0%
top 96.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN: slab-out-of-bounds in ses_intf_remove+0x23f/0x270 [ses] Read of size 8 at addr ffff88a10d32e5d8 by task rmmod/12013 When edev->components is zero, accessing edev->component[0] members is wrong.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDlinux/linux_kernel2.6.254.14.308+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux9927c68864e9c39cc317b4f559309ba29e64216876f7050537476ac062ec23a544fbca8270f2d08b+8
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53521: In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN: slab2025-10-01
GHSA
GHSA-wgq5-3g38-q2mr: In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN: s2025-10-01

📋Vendor Advisories

2
Red Hat
kernel: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove()2025-10-01
Debian
CVE-2023-53521: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: ses: ...2023