« Volver al listado

CVE-2023-53464

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

scsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()

The validity of sock should be checked before assignment to avoid incorrect values. Commit 57569c37f0ad ("scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername()") introduced this change which may lead to inconsistent values of tcp_sw_conn->sendpage and conn->datadgst_en.

Fix the issue by moving the position of the assignment.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53464",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "884a788f065578bb640382279a83d1df433b13e6",
              "lessThan": "499757ad3332e2527254f9ab68dec1da087b1d96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a26b0658751bb0a3b28386fca715333b104d32a2",
              "lessThan": "5e5c5f472972c4bc9430adc08b36763a0fa5b9f7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57569c37f0add1b6489e1a1563c71519daf732cf",
              "lessThan": "6e06a68fbbfcd8576eee8f7139fa2b13c9b72e91",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57569c37f0add1b6489e1a1563c71519daf732cf",
              "lessThan": "b287e21e73ec23f3788fbe40037c42dbe6e9a9a9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57569c37f0add1b6489e1a1563c71519daf732cf",
              "lessThan": "48b19b79cfa37b1e50da3b5a8af529f994c08901",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "897dbbc57d71e8a34ec1af8e573a142de457da38",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0a0b861fce2657ba08ec356a74346b37ca4b2008",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.150",
              "lessThan": "5.10.178",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.75",
              "lessThan": "5.15.107",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.19.17",
              "lessThan": "5.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.0.3",
              "lessThan": "6.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/scsi/iscsi_tcp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.178",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.107",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.24",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/scsi/iscsi_tcp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-10-01T12:15:48.267",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/48b19b79cfa37b1e50da3b5a8af529f994c08901",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/499757ad3332e2527254f9ab68dec1da087b1d96",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5e5c5f472972c4bc9430adc08b36763a0fa5b9f7",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e06a68fbbfcd8576eee8f7139fa2b13c9b72e91",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b287e21e73ec23f3788fbe40037c42dbe6e9a9a9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: iscsi_tcp: Check that sock is valid before iscsi_set_param()\n\nThe validity of sock should be checked before assignment to avoid incorrect\nvalues. Commit 57569c37f0ad (\"scsi: iscsi: iscsi_tcp: Fix null-ptr-deref\nwhile calling getpeername()\") introduced this change which may lead to\ninconsistent values of tcp_sw_conn->sendpage and conn->datadgst_en.\n\nFix the issue by moving the position of the assignment."
    }
  ],
  "lastModified": "2026-06-17T06:45:24.203",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "351EE6BF-CF90-41B2-B1D1-5E944AD2D232",
              "versionEndExcluding": "5.10.178",
              "versionStartIncluding": "5.10.150"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7C8D3CB-B4CD-4C39-AB50-2406B2348010",
              "versionEndExcluding": "5.15.107",
              "versionStartIncluding": "5.15.75"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6817F83D-0EC4-49B2-AAB2-1836D288AE4E",
              "versionEndExcluding": "6.0",
              "versionStartIncluding": "5.19.17"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B25680A-F2C9-42CE-BAD3-E84314698719",
              "versionEndExcluding": "6.1.24",
              "versionStartIncluding": "6.0.3"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93C03C9A-798F-4CD5-912F-A436BFA0CC7E",
              "versionEndExcluding": "6.2.11",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8E3B0E8-FA27-4305-87BB-AF6C25B160CB"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A47F0FC3-CE52-4BA1-BA51-22F783938431"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.3:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3583026A-27EC-4A4C-850A-83F2AF970673"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.3:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC271202-7570-4505-89A4-D602D47BFD00"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.3:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D413BB6D-4F74-4C7D-9163-47786619EF53"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}