
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53510 is a vulnerability discovered in the Linux kernel's SCSI UFS core component, specifically related to the handling of lrbp->cmd in the ufshcd_queuecommand() function. The vulnerability was published on October 1, 2025, and affects various Linux kernel versions (NVD, Ubuntu).
The vulnerability occurs when ufshcd_queuecommand() may be called two times consecutively for a SCSI command before it is completed. The issue manifests in the functions that submit a command and in ufshcd_release_scsi_cmd(). When a command times out, it can trigger a warning at drivers/ufs/core/ufshcd.c:2965 ufshcd_queuecommand+0x6f8/0x9a8, followed by a specific call trace through various kernel functions (NVD).
The vulnerability affects multiple Linux distributions and kernel versions, particularly impacting SCSI UFS core functionality. Ubuntu has classified this as a medium priority vulnerability, with various kernel packages being affected across different Ubuntu releases (Ubuntu).
The vulnerability has been resolved through changes in the kernel code that modify how lrbp->cmd is handled. The fix includes: not checking the old value of lrbp->cmd nor clearing it in error paths during command submission, and not clearing lrbp->cmd in ufshcd_release_scsi_cmd() (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."