scsi: ses: Fix slab-out-of-bounds in ses_intf_remove()
Summary
| CVE | CVE-2023-53521 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-01 12:15:56 UTC |
| Updated | 2026-04-06 13:09:49 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_intf_remove() A fix for: BUG: KASAN: slab-out-of-bounds in ses_intf_remove+0x23f/0x270 [ses] Read of size 8 at addr ffff88a10d32e5d8 by task rmmod/12013 When edev->components is zero, accessing edev->component[0] members is wrong. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Problem Types: CWE-125
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 76f7050537476ac062ec23a544fbca8270f2d08b git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 87e47be38d205df338c52ead43f23b2864567423 git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 40af9a6deed723485e05b7d3255a28750692e8db git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 8f9542cad6c27297c8391de3a659f0b7948495d0 git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 0595cdb587726b4f0fa780eb7462e3679d141e82 git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 82143faf01dda831b89eccef60c39ef8575ab08a git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 2fb1fa8425cce2dc4dce298275d22d7077694b73 git | Not specified |
| CNA | Linux | Linux | affected 9927c68864e9c39cc317b4f559309ba29e642168 578797f0c8cbc2e3ec5fc0dab87087b4c7073686 git | Not specified |
| CNA | Linux | Linux | affected 2.6.25 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.25 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.14.308 4.14.* semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.276 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.235 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.173 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.99 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.16 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.2.3 6.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/578797f0c8cbc2e3ec5fc0dab87087b4c7073686 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/8f9542cad6c27297c8391de3a659f0b7948495d0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/82143faf01dda831b89eccef60c39ef8575ab08a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/2fb1fa8425cce2dc4dce298275d22d7077694b73 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/87e47be38d205df338c52ead43f23b2864567423 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/40af9a6deed723485e05b7d3255a28750692e8db | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/76f7050537476ac062ec23a544fbca8270f2d08b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/0595cdb587726b4f0fa780eb7462e3679d141e82 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.