cbcvebase.
CVE-2023-53521
published 2025-10-01

CVE-2023-53521: In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN: slab-out-of-bounds in ses_intf_remove+0x23f/0x270 [ses] Read of size 8 at addr ffff88a10d32e5d8 by task rmmod/12013 When edev->components is zero, accessing edev->component[0] members is wrong.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 76f7050537476ac062ec23a544fbca8270f2d08b76f7050537476ac062ec23a544fbca8270f2d08b
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 87e47be38d205df338c52ead43f23b286456742387e47be38d205df338c52ead43f23b2864567423
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 40af9a6deed723485e05b7d3255a28750692e8db40af9a6deed723485e05b7d3255a28750692e8db
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 8f9542cad6c27297c8391de3a659f0b7948495d08f9542cad6c27297c8391de3a659f0b7948495d0
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 0595cdb587726b4f0fa780eb7462e3679d141e820595cdb587726b4f0fa780eb7462e3679d141e82
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 82143faf01dda831b89eccef60c39ef8575ab08a82143faf01dda831b89eccef60c39ef8575ab08a
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 2fb1fa8425cce2dc4dce298275d22d7077694b732fb1fa8425cce2dc4dce298275d22d7077694b73
linuxlinux>= 9927c68864e9c39cc317b4f559309ba29e642168 < 578797f0c8cbc2e3ec5fc0dab87087b4c7073686578797f0c8cbc2e3ec5fc0dab87087b4c7073686
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 2.6.25 < 4.14.3084.14.308
linuxlinux_kernel>= 4.15 < 4.19.2764.19.276
linuxlinux_kernel>= 4.20 < 5.4.2355.4.235
linuxlinux_kernel>= 5.11 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 5.5 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.