Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-7324

Опубликовано: 29 окт. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

Отчет

The SES enclosure parser could read past the end of the additional descriptor buffer (page10) due to missing length checks. The fix passes max_desc_len into ses_process_descriptor(), adds per-branch minimum-length guards, and nulls addl_desc_ptr on failure, preventing OOB reads. Practical impact is local DoS during SES page parsing; triggering typically requires privileged access to SCSI enclosure controls.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2407075kernel: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses

EPSS

Процентиль: 21%
0.00289
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

CVSS3: 8.1
nvd
10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

CVSS3: 8.1
debian
10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 8.1
github
10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds accesses in ses_enclosure_data_process().

suse-cvrf
10 месяцев назад

Security update for the Linux Kernel

EPSS

Процентиль: 21%
0.00289
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2023-7324