CVE-2023-53803

Source
https://cve.org/CVERecord?id=CVE-2023-53803
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53803.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53803
Downstream
Related
Published
2025-12-09T00:00:59.913Z
Modified
2026-03-12T03:28:43.633211Z
Summary
scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: ses: Fix slab-out-of-bounds in sesenclosuredata_process()

A fix for:

BUG: KASAN: slab-out-of-bounds in sesenclosuredata_process+0x949/0xe30 [ses] Read of size 1 at addr ffff88a1b043a451 by task systemd-udevd/3271

Checking after (and before in next loop) addldescptr[1] is sufficient, we expect the size to be sanitized before first access to addldescptr[1]. Make sure we don't walk beyond end of page.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53803.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
21fab1d0595eacf781705ec3509012a28f298245
Fixed
da1a955c48a16e16e925d6544793914e52a6fa51
Fixed
9e5c7d52085b8c84bc82a261580f0eb170039325
Fixed
467afb1dd630d8c6d172bd6cacc125199b5f4f2d
Fixed
e4dd25da784b2e07dbfbf04509afa4c5a1375227
Fixed
2b28a7d261cb309912596d6a2d383ca370483527
Fixed
0dfe68394cbe1d4fe579fb325ecc813c50528c5a
Fixed
799e8dd2022d2e13f0c5c1906b40ceca07a23349
Fixed
9b4f5028e493cb353a5c8f5c45073eeea0303abd

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53803.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.32
Fixed
4.14.308
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.276
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.235
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.173
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.99
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.16
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53803.json"