๐Ÿ” CVE Alert

CVE-2023-53387

MEDIUM 5.5

scsi: ufs: core: Fix device management cmd timeout flow

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix device management cmd timeout flow In the UFS error handling flow, the host will send a device management cmd (NOP OUT) to the device for link recovery. If this cmd times out and clearing the doorbell fails, ufshcd_wait_for_dev_cmd() will do nothing and return. hba->dev_cmd.complete struct is not set to NULL. When this happens, if cmd has been completed by device, then we will call complete() in __ufshcd_transfer_req_compl(). Because the complete struct is allocated on the stack, the following crash will occur: ipanic_die+0x24/0x38 [mrdump] die+0x344/0x748 arm64_notify_die+0x44/0x104 do_debug_exception+0x104/0x1e0 el1_dbg+0x38/0x54 el1_sync_handler+0x40/0x88 el1_sync+0x8c/0x140 queued_spin_lock_slowpath+0x2e4/0x3c0 __ufshcd_transfer_req_compl+0x3b0/0x1164 ufshcd_trc_handler+0x15c/0x308 ufshcd_host_reset_and_restore+0x54/0x260 ufshcd_reset_and_restore+0x28c/0x57c ufshcd_err_handler+0xeb8/0x1b6c process_one_work+0x288/0x964 worker_thread+0x4bc/0xc7c kthread+0x15c/0x264 ret_from_fork+0x10/0x30

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 18, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new medium vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
f5c2976e0cb0f6236013bfb479868531b04f61d4 < cf45493432704786a0f8294c7723ad4eeb5fff24 f5c2976e0cb0f6236013bfb479868531b04f61d4 < 3ffd2cd644e0f1eea01339831bac4b1054e8817c f5c2976e0cb0f6236013bfb479868531b04f61d4 < 36822124f9de200cedc2f42516301b50d386a6cd 8841c1b02c8083e4451077a2b1f235bbfd0db105
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/cf45493432704786a0f8294c7723ad4eeb5fff24 git.kernel.org: https://git.kernel.org/stable/c/3ffd2cd644e0f1eea01339831bac4b1054e8817c git.kernel.org: https://git.kernel.org/stable/c/36822124f9de200cedc2f42516301b50d386a6cd