Junglewise Threat Intelligence

CVE-2023-53675: Linux kernel SCSI SES out-of-bounds buffer access

CVE-2023-53675 · Severity: high · CVSS 8.8 · Published 2025-10-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SCSI Enclosure Services (SES) driver contains a buffer boundary validation flaw in its enclosure data processing function. An attacker with local or physical access to craft malicious SES device responses could trigger out-of-bounds memory reads or writes, potentially leading to system crashes, information disclosure, or privilege escalation on systems managing SCSI enclosures.

Technical details

The vulnerability is a bounds-checking flaw in the `ses_enclosure_data_process()` function in drivers/scsi/ses.c. The code improperly validated the `desc_ptr` pointer against buffer boundaries before dereferencing it to read a length value and subsequently accessing descriptor data. An attacker could provide malformed SES device responses with crafted descriptor offsets to trigger out-of-bounds reads or writes. The vulnerability requires access to a SCSI device (local or adjacent network access depending on transport), and patches add proper bounds validation via two sequential checks: first verifying the header is within bounds (desc_ptr + 3), then verifying the full descriptor data is within bounds (desc_ptr + len).

Affected products

  • Linux Linux kernel Affected versions through 2023-02-02; patched in stable branches via commit 414418abc19fa4ccf730d273061a426c07a061d6

Timeline

  • 2023-02-02: disclosed: Vulnerability reported and initial patch authored by Tomas Henzl
  • 2023-03-10: patched: Fix merged into Linux kernel stable trees
  • 2025-10-07: advisory: CVE-2023-53675 assigned and published to NVD

References

Related threats