CVE Database
/

CVE-2023-52515

Back to search

CVE-2023-52515

Published: Mar 2, 2024

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queue_insert(). * Call scsi_finish_command(). * Call scsi_eh_scmd_add(). Hence, SCSI abort handlers must not call scsi_done(). Otherwise all the above actions would trigger a use-after-free. Hence remove the scsi_done() call from srp_abort(). Keep the srp_free_req() call before returning SUCCESS because we may not see the command again if SUCCESS is returned.

VendorProductVersions

Linux

Linux

affected
d8536670916a685df116b5c2cb256573fd25e4e3 - < 26788a5b48d9d5cd3283d777d238631c8cd7495a
affected
d8536670916a685df116b5c2cb256573fd25e4e3 - < b9bdffb3f9aaeff8379c83f5449c6b42cb71c2b5
affected
d8536670916a685df116b5c2cb256573fd25e4e3 - < 2b298f9181582270d5e95774e5a6c7a7fb5b1206
affected
d8536670916a685df116b5c2cb256573fd25e4e3 - < 05a10b316adaac1f322007ca9a0383b410d759cc
affected
d8536670916a685df116b5c2cb256573fd25e4e3 - < e193b7955dfad68035b983a0011f4ef3590c85eb

+10 more versions

Linux

Linux

affected
3.7
unaffected
0 - < 3.7
unaffected
5.10.199 - <= 5.10.*
unaffected
5.15.136 - <= 5.15.*
unaffected
6.1.57 - <= 6.1.*

+2 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now