In the Linux kernel, the following vulnerability has been resolved:
scsi: ses: Fix slab-out-of-bounds in sesintfremove()
A fix for:
BUG: KASAN: slab-out-of-bounds in sesintfremove+0x23f/0x270 [ses] Read of size 8 at addr ffff88a10d32e5d8 by task rmmod/12013
When edev->components is zero, accessing edev->component[0] members is wrong.
{ "vanir_signatures": [ { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@87e47be38d205df338c52ead43f23b2864567423", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-05b3b2df" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0595cdb587726b4f0fa780eb7462e3679d141e82", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-087b51af" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@578797f0c8cbc2e3ec5fc0dab87087b4c7073686", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-2db8366a" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0595cdb587726b4f0fa780eb7462e3679d141e82", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-5550de09" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76f7050537476ac062ec23a544fbca8270f2d08b", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-55c6bb26" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@87e47be38d205df338c52ead43f23b2864567423", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-6eb9d375" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82143faf01dda831b89eccef60c39ef8575ab08a", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-83ff5f24" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fb1fa8425cce2dc4dce298275d22d7077694b73", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-8eae12c3" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@40af9a6deed723485e05b7d3255a28750692e8db", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-930f881f" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@40af9a6deed723485e05b7d3255a28750692e8db", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-bd569a0c" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76f7050537476ac062ec23a544fbca8270f2d08b", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-d6569939" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82143faf01dda831b89eccef60c39ef8575ab08a", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-dca6523b" }, { "digest": { "length": 390.0, "function_hash": "76783162190030363135945358165297017248" }, "target": { "function": "ses_intf_remove_enclosure", "file": "drivers/scsi/ses.c" }, "signature_type": "Function", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@578797f0c8cbc2e3ec5fc0dab87087b4c7073686", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-e63d0498" }, { "digest": { "line_hashes": [ "268188463623391904594862509470490890495", "252633646091478076468275111640900001121", "143990604088432813173071290108486306791", "82980957273392539519229781453970250455" ], "threshold": 0.9 }, "target": { "file": "drivers/scsi/ses.c" }, "signature_type": "Line", "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2fb1fa8425cce2dc4dce298275d22d7077694b73", "deprecated": false, "signature_version": "v1", "id": "CVE-2023-53521-ffeec502" } ] }