CVE-2023-53140

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier Remove the /proc/scsi/${proc_name} directory earlier to fix a race condition between unloading and reloading kernel modules. This fixes a bug introduced in 2009 by commit 77c019768f06 ("[SCSI] fix /proc memory leak in the SCSI core"). Fix the following kernel warning: proc_dir_entry 'scsi/scsi_debug' already registered WARNING: CPU: 19 PID: 27986 at fs/proc/generic.c:376 proc_register+0x27d/0x2e0 Call Trace: proc_mkdir+0xb5/0xe0 scsi_proc_hostdir_add+0xb5/0x170 scsi_host_alloc+0x683/0x6c0 sdebug_driver_probe+0x6b/0x2d0 [scsi_debug] really_probe+0x159/0x540 __driver_probe_device+0xdc/0x230 driver_probe_device+0x4f/0x120 __device_attach_driver+0xef/0x180 bus_for_each_drv+0xe5/0x130 __device_attach+0x127/0x290 device_initial_probe+0x17/0x20 bus_probe_device+0x110/0x130 device_add+0x673/0xc80 device_register+0x1e/0x30 sdebug_add_host_helper+0x1a7/0x3b0 [scsi_debug] scsi_debug_init+0x64f/0x1000 [scsi_debug] do_one_initcall+0xd7/0x470 do_init_module+0xe7/0x330 load_module+0x122a/0x12c0 __do_sys_finit_module+0x124/0x1a0 __x64_sys_finit_module+0x46/0x50 do_syscall_64+0x38/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

10 Nov 2025, 17:38

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/13daafe1e209b03e9bda16ff2bd2b2da145a139b - () https://git.kernel.org/stable/c/13daafe1e209b03e9bda16ff2bd2b2da145a139b - Patch
References () https://git.kernel.org/stable/c/17e98a5ede81b7696bec421f7afa2dfe467f5e6b - () https://git.kernel.org/stable/c/17e98a5ede81b7696bec421f7afa2dfe467f5e6b - Patch
References () https://git.kernel.org/stable/c/1ec363599f8346d5a8d08c71a0d9860d6c420ec0 - () https://git.kernel.org/stable/c/1ec363599f8346d5a8d08c71a0d9860d6c420ec0 - Patch
References () https://git.kernel.org/stable/c/6b223e32d66ca9db1f252f433514783d8b22a8e1 - () https://git.kernel.org/stable/c/6b223e32d66ca9db1f252f433514783d8b22a8e1 - Patch
References () https://git.kernel.org/stable/c/891a3cba425cf483d96facca55aebd6ff1da4338 - () https://git.kernel.org/stable/c/891a3cba425cf483d96facca55aebd6ff1da4338 - Patch
References () https://git.kernel.org/stable/c/e471e928de97b00f297ad1015cc14f9459765713 - () https://git.kernel.org/stable/c/e471e928de97b00f297ad1015cc14f9459765713 - Patch
References () https://git.kernel.org/stable/c/fc663711b94468f4e1427ebe289c9f05669699c9 - () https://git.kernel.org/stable/c/fc663711b94468f4e1427ebe289c9f05669699c9 - Patch
CWE CWE-401
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

05 May 2025, 20:54

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: scsi: core: Eliminar el directorio /proc/scsi/${proc_name} antes. Eliminar el directorio /proc/scsi/${proc_name} antes para corregir una condición de ejecución entre la descarga y la recarga de módulos del kernel. Esto corrige un error introducido en 2009 por el commit 77c019768f06 ("[SCSI] corregir fuga de memoria de /proc en el núcleo SCSI"). Corrija la siguiente advertencia del kernel: proc_dir_entry 'scsi/scsi_debug' ya está registrado ADVERTENCIA: CPU: 19 PID: 27986 en fs/proc/generic.c:376 proc_register+0x27d/0x2e0 Seguimiento de llamadas: proc_mkdir+0xb5/0xe0 scsi_proc_hostdir_add+0xb5/0x170 scsi_host_alloc+0x683/0x6c0 sdebug_driver_probe+0x6b/0x2d0 [scsi_debug] really_probe+0x159/0x540 __driver_probe_device+0xdc/0x230 driver_probe_device+0x4f/0x120 __device_attach_driver+0xef/0x180 bus_for_each_drv+0xe5/0x130 __device_attach+0x127/0x290 device_initial_probe+0x17/0x20 bus_probe_device+0x110/0x130 device_add+0x673/0xc80 device_register+0x1e/0x30 sdebug_add_host_helper+0x1a7/0x3b0 [scsi_debug] scsi_debug_init+0x64f/0x1000 [scsi_debug] do_one_initcall+0xd7/0x470 do_init_module+0xe7/0x330 load_module+0x122a/0x12c0 __do_sys_finit_module+0x124/0x1a0 __x64_sys_finit_module+0x46/0x50 do_syscall_64+0x38/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0

02 May 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 16:15

Updated : 2025-11-10 17:38


NVD link : CVE-2023-53140

Mitre link : CVE-2023-53140

CVE.ORG link : CVE-2023-53140


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime