-

CVE-2023-53521

In the Linux kernel, the following vulnerability has been resolved:

scsi: ses: Fix slab-out-of-bounds in ses_intf_remove()

A fix for:

BUG: KASAN: slab-out-of-bounds in ses_intf_remove+0x23f/0x270 [ses]
Read of size 8 at addr ffff88a10d32e5d8 by task rmmod/12013

When edev->components is zero, accessing edev->component[0] members is
wrong.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 76f7050537476ac062ec23a544fbca8270f2d08b
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 87e47be38d205df338c52ead43f23b2864567423
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 40af9a6deed723485e05b7d3255a28750692e8db
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 8f9542cad6c27297c8391de3a659f0b7948495d0
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 0595cdb587726b4f0fa780eb7462e3679d141e82
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 82143faf01dda831b89eccef60c39ef8575ab08a
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 2fb1fa8425cce2dc4dce298275d22d7077694b73
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 578797f0c8cbc2e3ec5fc0dab87087b4c7073686
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version <= 4.14.*
Version 4.14.308
Status unaffected
Version <= 4.19.*
Version 4.19.276
Status unaffected
Version <= 5.4.*
Version 5.4.235
Status unaffected
Version <= 5.10.*
Version 5.10.173
Status unaffected
Version <= 5.15.*
Version 5.15.99
Status unaffected
Version <= 6.1.*
Version 6.1.16
Status unaffected
Version <= 6.2.*
Version 6.2.3
Status unaffected
Version <= *
Version 6.3
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.081
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String