PT-2025-18820 · Linux+5 · Linux Kernel+5

Published

2023-03-12

·

Updated

2026-01-28

·

CVE-2023-53056

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A system hang was observed due to the IOCB counts being out of order, blocking commands and subsequently hanging the system. The issue was resolved by synchronizing the IOCB count to be in the correct order. A kernel NULL pointer dereference was also observed, which was addressed by the same fix.
Recommendations For Linux kernel versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider disabling the qla nvme ls req function until a patch is available. Restrict access to the vulnerable nvme fc module to minimize the risk of exploitation. Avoid using the nvme fc xmt disconnect assoc function in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06839
CESA-2023_7077
CVE-2023-53056
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:01918-1
SUSE-SU-2025:01966-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02173-1
SUSE-SU-2025:02262-1
SUSE-SU-2025:2173-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02173-1
SUSE-SU-2025_02262-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse