VYPR
High severity7.8NVD Advisory· Published May 2, 2025· Updated Jun 17, 2026

CVE-2023-53037

CVE-2023-53037

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpi3mr: Bad drive in topology results kernel crash

When the SAS Transport Layer support is enabled and a device exposed to the OS by the driver fails INQUIRY commands, the driver frees up the memory allocated for an internal HBA port data structure. However, in some places, the reference to the freed memory is not cleared. When the firmware sends the Device Info change event for the same device again, the freed memory is accessed and that leads to memory corruption and OS crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Linux/Kernel4 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.14,<6.1.22
    • cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 5.14
  • osv-coords
    Range: >= 5.14.0, < 6.1.22

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.