CVE-2023-53530
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53530 is a vulnerability in the Linux kernel that was discovered and published on October 1, 2025. The issue involves the improper use of smp_processor_id() in preemptible code within the qla2xxx SCSI driver. This vulnerability affects various Linux kernel versions and distributions (NVD, Ubuntu).

Technical details

The vulnerability occurs in the Linux kernel's SCSI qla2xxx driver where smp_processor_id() is used instead of raw_smp_processor_id() in preemptible code. The issue was identified when a call trace showed the improper usage in the qla_nvme_post_cmd function. The bug manifests when CONFIG_DEBUG_PREEMPT is enabled, potentially leading to system instability (NVD).

Impact

The vulnerability can cause system instability and potential crashes when running with CONFIG_DEBUG_PREEMPT enabled. This affects various Linux distributions and kernel versions, particularly impacting systems using the qla2xxx SCSI driver (Ubuntu).

Mitigation and workarounds

The fix involves replacing smp_processor_id() with raw_smp_processor_id() and using queue_work() instead of queue_work_on() across the driver. Several Linux distributions have released patches, including Ubuntu which has fixed the issue in various kernel versions such as linux-hwe-5.15 (5.15.0-94.104~20.04.1) (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-cross-headers
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-core
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management