Review reviewHigh

CVE-2023-7324

Linux

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

CVSS
8.1
EPSS
0.29%
21.4% percentile
CISA KEV
Not listed
Published
2025.10.29
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.29%
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

Affected product and versions

Product
Linux
Affected versions
>= 9927c68864e9c39cc317b4f559309ba29e642168 < af5114d824f3511a69d68beff49ca9a7c32d44e0, >= 9927c68864e9c39cc317b4f559309ba29e642168 < a156a262c543fa5ff30bcb2fc6ad1a95cb4ab57a, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 8e454aba72805241239caf8ba9b8e5a6be772b96, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 2ecd344173a5663d523433819da0484cb268b186, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 384aa697d8f2a28b5e962f5292cdfd2e528b5df7, >= 9927c68864e9c39cc317b4f559309ba29e642168 < 27067c672980b497cc34048b69b12820851ac6b9, >= 9927c68864e9c39cc317b4f559309ba29e642168 < b91ef85a32fdba45fcbad87dd526d73d3b6d857d, >= 9927c68864e9c39cc317b4f559309ba29e642168 < db95d4df71cb55506425b6e4a5f8d68e3a765b63, >= 2.6.25
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
Not available