Aller au contenu

Fiche vulnérabilité

CVE-2023-53037 : faille élevée linux linux kernel (CVSS 7.8)

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Bad drive in topology results kernel crash When the SAS Transport Layer support is enabled and a device exposed to the OS by the driver fails INQUIRY commands, the driver frees up the memory allocated for an internal HBA port data structure. However, in some places, the reference to the freed memory is not cleared. When the firmware sends the Device Info change event for the same device again, the freed memory is accessed and that leads to memory corruption and OS crash.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
2 mai 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE