CVE-2023-53387

MEDIUM EPSS 3.2%
Published Sep 18, 20259mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Sep 18, 2025 9mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix device management cmd timeout flow In the UFS error handling flow, the host will send a device management cmd (NOP OUT) to the device for link recovery. If this cmd times out and clearing the doorbell fails, ufshcd_wait_for_dev_cmd() will do nothing and return. hba->dev_cmd.complete struct is not set to NULL. When this happens, if cmd has been completed by device, then we will call complete() in __ufshcd_transfer_req_compl(). Because the complete struct is allocated on the stack, the following crash will occur: ipanic_die+0x24/0x38 [mrdump] die+0x344/0x748 arm64_notify_die+0x44/0x104 do_debug_exception+0x104/0x1e0 el1_dbg+0x38/0x54 el1_sync_handler+0x40/0x88 el1_sync+0x8c/0x140 queued_spin_lock_slowpath+0x2e4/0x3c0 __ufshcd_transfer_req_compl+0x3b0/0x1164 ufshcd_trc_handler+0x15c/0x308 ufshcd_host_reset_and_restore+0x54/0x260 ufshcd_reset_and_restore+0x28c/0x57c ufshcd_err_handler+0xeb8/0x1b6c process_one_work+0x288/0x964 worker_thread+0x4bc/0xc7c kthread+0x15c/0x264 ret_from_fork+0x10/0x30

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
3.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel* <6.1.16
linuxlinux_kernel*≥6.2  –  <6.2.3

References 3

  • git.kernel.org https://git.kernel.org/stable/c/36822124f9de200cedc2f42516301b50d386a6cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3ffd2cd644e0f1eea01339831bac4b1054e8817c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf45493432704786a0f8294c7723ad4eeb5fff24
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/36822124f9de200cedc2f42516301b50d386a6cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3ffd2cd644e0f1eea01339831bac4b1054e8817c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cf45493432704786a0f8294c7723ad4eeb5fff24
    Patch