CVE-2023-54154
published 2025-12-24CVE-2023-54154: In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix target_cmd_counter leak The target_cmd_counter struct allocated via…
PriorityP419low5.5
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct allocated via target_alloc_cmd_counter() is
never freed, resulting in leaks across various transport types, e.g.:
unreferenced object 0xffff88801f920120 (size 96):
comm "sh", pid 102, jiffies 4294892535 (age 713.412s)
hex dump (first 32 bytes):
07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8.......
backtrace:
[] kmalloc_trace+0x11/0x20
[] target_alloc_cmd_counter+0x17/0x90 [target_core_mod]
[] target_setup_session+0x2d/0x140 [target_core_mod]
[] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop]
[] configfs_write_iter+0xb1/0x120
[] vfs_write+0x2e4/0x3c0
[] ksys_write+0x80/0xb0
[] do_syscall_64+0x42/0x90
[] entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Free the structure alongside the corresponding iscsit_conn / se_sess
parent.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 6.1.28 < 6.1.55 | 6.1.55 |
| linux | linux | >= 6.2.15 < 6.3 | 6.3 |
| linux | linux | >= 6.3.2 < 6.4 | 6.4 |
| linux | linux | >= 76b77646f17118f5babe93c032e6b7a53bbde3b9 < 1cd41d1669bcbc5052afa897f85608a62ff3fb30 | 1cd41d1669bcbc5052afa897f85608a62ff3fb30 |
| linux | linux | >= becd9be6069e7b183c084f460f0eb363e43cc487 < f84639c5ac5f4f95b3992da1af4ff382ebf2e819 | f84639c5ac5f4f95b3992da1af4ff382ebf2e819 |
| linux | linux | >= becd9be6069e7b183c084f460f0eb363e43cc487 < d14e3e553e05cb763964c991fe6acb0a6a1c6f9c | d14e3e553e05cb763964c991fe6acb0a6a1c6f9c |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.1.55 | 6.1.55 |
| linux | linux_kernel | >= 6.2.0 < 6.5.5 | 6.5.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54154: In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix target_cmd_counter leak The target_cmd_counter struct allo
osv·2025-12-24
CVE-2023-54154 CVE-2023-54154: In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix target_cmd_counter leak The target_cmd_counter struct allo
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix target_cmd_counter leak The target_cmd_counter struct allocated via target_alloc_cmd_counter() is never freed, resulting in leaks across various transport types, e.g.: unreferenced object 0xffff88801f920120 (size 96): comm "sh", pid 102, jiffies 4294892535 (age 713.412s) hex dump (first 32 bytes): 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8....... backtrace: [] kmalloc_trace+0x11/0x20 [] target_alloc_cmd_counter+0x17/0x90 [target_core_mod] [] target_setup_session+0x2d/0x140 [target_core_mod] [] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop] [] configfs_write_iter+0xb1/0x120 [] vfs_write+0x2e4/0x3c0 [] ksys_write+0x80/0xb
GHSA
GHSA-35f8-m7gp-7vmp: In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct al
ghsa_unreviewed·2025-12-24
CVE-2023-54154 GHSA-35f8-m7gp-7vmp: In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct al
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct allocated via target_alloc_cmd_counter() is
never freed, resulting in leaks across various transport types, e.g.:
unreferenced object 0xffff88801f920120 (size 96):
comm "sh", pid 102, jiffies 4294892535 (age 713.412s)
hex dump (first 32 bytes):
07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8.......
backtrace:
[] kmalloc_trace+0x11/0x20
[] target_alloc_cmd_counter+0x17/0x90 [target_core_mod]
[] target_setup_session+0x2d/0x140 [target_core_mod]
[] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop]
[] configfs_write_iter+0xb1/0x120
[] vfs_write+0x2e4/0x3c0
[] ksys_write+0x80/
OSV
scsi: target: core: Fix target_cmd_counter leak
osv·2025-12-24
CVE-2023-54154 scsi: target: core: Fix target_cmd_counter leak
scsi: target: core: Fix target_cmd_counter leak
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct allocated via target_alloc_cmd_counter() is
never freed, resulting in leaks across various transport types, e.g.:
unreferenced object 0xffff88801f920120 (size 96):
comm "sh", pid 102, jiffies 4294892535 (age 713.412s)
hex dump (first 32 bytes):
07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8.......
backtrace:
[] kmalloc_trace+0x11/0x20
[] target_alloc_cmd_counter+0x17/0x90 [target_core_mod]
[] target_setup_session+0x2d/0x140 [target_core_mod]
[] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop]
[] configfs_write_iter+0xb1/0
Red Hat
kernel: Linux kernel: Denial of Service due to memory leak in target_cmd_counter
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54154 [LOW] CWE-772 kernel: Linux kernel: Denial of Service due to memory leak in target_cmd_counter
kernel: Linux kernel: Denial of Service due to memory leak in target_cmd_counter
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix target_cmd_counter leak
The target_cmd_counter struct allocated via target_alloc_cmd_counter() is
never freed, resulting in leaks across various transport types, e.g.:
unreferenced object 0xffff88801f920120 (size 96):
comm "sh", pid 102, jiffies 4294892535 (age 713.412s)
hex dump (first 32 bytes):
07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8.......
backtrace:
[] kmalloc_trace+0x11/0x20
[] target_alloc_cmd_counter+0x17/0x90 [target_core_mod]
[] target_setup_session+0x2d/0x140 [target_core_mod]
[] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop]
Debian
CVE-2023-54154: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: targe...
vendor_debian·2023
CVE-2023-54154 CVE-2023-54154: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: targe...
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix target_cmd_counter leak The target_cmd_counter struct allocated via target_alloc_cmd_counter() is never freed, resulting in leaks across various transport types, e.g.: unreferenced object 0xffff88801f920120 (size 96): comm "sh", pid 102, jiffies 4294892535 (age 713.412s) hex dump (first 32 bytes): 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff ........8....... backtrace: [] kmalloc_trace+0x11/0x20 [] target_alloc_cmd_counter+0x17/0x90 [target_core_mod] [] target_setup_session+0x2d/0x140 [target_core_mod] [] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop] [] configfs_write_iter+0xb1/0x120 [] vfs_write+0x2e4/0x3c0 [] ksys_write+0x80/0xb
No detection rules found.
No public exploits indexed.
2025-12-24
Published