PT-2025-38366 · Linux+1 · Linux Kernel+1

Published

2025-09-18

·

Updated

2026-04-20

·

CVE-2023-53387

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the UFS error handling flow within the Linux kernel. Specifically, if a device management command (NOP OUT) times out during link recovery and clearing the doorbell fails, the ufshcd wait for dev cmd() function may return without properly resetting the complete structure. Subsequently, if the command is completed by the device, calling complete() within ufshcd transfer req compl() can lead to a crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-06026
CVE-2023-53387
RHSA-2023:6583

Affected Products

Debian
Linux Kernel