CVE-2023-53530
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability has been identified and resolved involving the improper use of smpprocessorid() instead of rawsmpprocessorid() in the qla2xxx SCSI driver. The issue was discovered when a call trace was observed during NVME-FC controller connection, showing the use of smpprocessor_id() in preemptible code (NVD).

Technical details

The vulnerability manifests in the qlanvmepostcmd function of the qla2xxx driver, where smpprocessorid() was incorrectly used in preemptible code. The issue occurs specifically when CONFIGDEBUGPREEMPT is enabled. The fix involves replacing smpprocessorid() with rawsmpprocessorid() and modifying the driver to use queuework() instead of queueworkon() to avoid smpprocessor_id() usage in preemptible contexts (NVD).

Impact

When triggered, this vulnerability can cause system instability and potential crashes, as evidenced by the BUG warning message observed in the kernel logs. The issue affects systems running the Linux kernel with the qla2xxx driver, particularly in configurations using NVME-FC storage (NVD).

Mitigation and workarounds

The vulnerability has been addressed through a kernel patch that replaces smpprocessorid() with rawsmpprocessorid() and modifies the queuework implementation. Users should update to the patched version of the Linux kernel to mitigate this issue (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-53532N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-core
NoYesOct 01, 2025
CVE-2023-53531N/AN/A
  • Linux KernelLinux Kernel
  • kernel-selftests-internal
NoYesOct 01, 2025
CVE-2023-53530N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesOct 01, 2025
CVE-2023-53529N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesOct 01, 2025
CVE-2023-53528N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesOct 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management