Review reviewHigh

CVE-2023-53675

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible desc_ptr out-of-bounds accesses Sanitize possible desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

CVSS
7.1
EPSS
0.20%
10.3% percentile
CISA KEV
Not listed
Published
2025.10.08
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.20%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible desc_ptr out-of-bounds accesses Sanitize possible desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 9927c68864e9c39cc317b4f559309ba29e642168 < 72021ae61a2bc6ca73cd593e255a10ed5f5dc5e7, >= 9927c68864e9c39cc317b4f559309ba29e642168 < cffe09ca0555e235a42d6fa065e463c4b3d5b657, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 79ec5dd5fb07ecaea2f978c2d7a9f2f3526e4d19, >= 9927c68864e9c39cc317b4f559309ba29e642168 < c315560e3ef77c1d822249f1743e647dc9c9912a, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 584892fd29a41ef424a148118a3103b16b94fb8c, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 414418abc19fa4ccf730d273061a426c07a061d6, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 4b8cae410472653a59e15af62c57c49b8e0a1201, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 801ab13d50cf3d26170ee073ea8bb4eececb76ab, >= 2.6.25, >= 2.6.25 < 4.14.308, >= 4.15 < 4.19.276, >= 4.20 < 5.4.235, >= 5.5 < 5.10.173, >= 5.11 < 5.15.99, >= 5.16 < 6.1.16, >= 6.2 < 6.2.3
Fixed versions
4.14.308, 4.19.276, 5.4.235, 5.10.173, 5.15.99, 6.1.16, 6.2.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125