PT-2025-40749 · Linux+2 · Linux Kernel+2

Published

2024-04-30

·

Updated

2026-02-10

·

CVE-2023-53586

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s SCSI target handling of LUN RESET commands. The issue arises when multiple LUN RESET commands are received from different initiators, leading to a scenario where an initiator incorrectly believes running commands have been cleaned up, even when they haven't. This can result in commands being restarted and potentially lead to invalid ITT errors or accidental task lookups. The root cause is related to how commands are managed and removed from lists during the LUN RESET process, specifically introduced by commit 51ec502a3266. The fix involves reverting the problematic patch and serializing the execution of LUN RESETs, Preempts, and Aborts. Additionally, the fix prevents waiting on LUN RESETs within core tmr drain tmr list to avoid potential deadlocks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
CESA-2024_3138
CVE-2023-53586
RHSA-2024:2394
RHSA-2024:3138
RHSA-2024_2394
RHSA-2024_3138

Affected Products

Centos
Linux Kernel
Red Hat