๐Ÿ” CVE Alert

CVE-2023-52974

HIGH 7.8

scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress If during iscsi_sw_tcp_session_create() iscsi_tcp_r2tpool_alloc() fails, userspace could be accessing the host's ipaddress attr. If we then free the session via iscsi_session_teardown() while userspace is still accessing the session we will hit a use after free bug. Set the tcp_sw_host->session after we have completed session creation and can no longer fail.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Mar 27, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < 496af9d3682ed4c28fb734342a09e6cc0c056ea4 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < 6abd4698f4c8a78e7bbfc421205c060c199554a0 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < d4d765f4761f9e3a2d62992f825aeee593bcb6b9 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < 9758ffe1c07b86aefd7ca8e40d9a461293427ca0 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < 0aaabdb900c7415caa2006ef580322f7eac5f6b6 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < 61e43ebfd243bcbad11be26bd921723027b77441 a79af8a64d395bd89de8695a5ea5e1a7f01f02a8 < f484a794e4ee2a9ce61f52a78e810ac45f3fe3b3
Linux / Linux
2.6.39

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/496af9d3682ed4c28fb734342a09e6cc0c056ea4 git.kernel.org: https://git.kernel.org/stable/c/6abd4698f4c8a78e7bbfc421205c060c199554a0 git.kernel.org: https://git.kernel.org/stable/c/d4d765f4761f9e3a2d62992f825aeee593bcb6b9 git.kernel.org: https://git.kernel.org/stable/c/9758ffe1c07b86aefd7ca8e40d9a461293427ca0 git.kernel.org: https://git.kernel.org/stable/c/0aaabdb900c7415caa2006ef580322f7eac5f6b6 git.kernel.org: https://git.kernel.org/stable/c/61e43ebfd243bcbad11be26bd921723027b77441 git.kernel.org: https://git.kernel.org/stable/c/f484a794e4ee2a9ce61f52a78e810ac45f3fe3b3