PT-2025-53194 · Linux · Linux Kernel

Published

2025-12-24

·

Updated

2026-03-24

·

CVE-2023-54117

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the s390/dcssblk subsystem, potentially leading to a kernel crash due to list add corruption. The issue stems from missing dax remove host() calls and incorrect error handling within the dax add host() function, introduced by commit fb08a1908cb1. This can result in stale xarray entries during device add/remove cycles. Specifically, a previously used gendisk pointer might be reused, causing xa insert() to fail and leading to an extra put device() call in the error path. Combined with existing error handling issues in dcssblk, this can cause a missing device del()/klist del(), ultimately triggering a kernel crash with list add corruption during subsequent device add/klist add operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-54117
RHSA-2025:6966
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

Linux Kernel