{"id":"DEBIAN-CVE-2023-53320","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info()  The function mpi3mr_get_all_tgt_info() has four issues:  1) It calculates valid entry length in alltgt_info assuming the header part    of the struct mpi3mr_device_map_info would equal to sizeof(u32).  The    correct size is sizeof(u64).  2) When it calculates the valid entry length kern_entrylen, it excludes one    entry by subtracting 1 from num_devices.  3) It copies num_device by calling memcpy(). Substitution is enough.  4) It does not specify the calculated length to sg_copy_from_buffer().    Instead, it specifies the payload length which is larger than the    alltgt_info size. It causes \"BUG: KASAN: slab-out-of-bounds\".  Fix the issues by using the correct header size, removing the subtraction from num_devices, replacing the memcpy() with substitution and specifying the correct length to sg_copy_from_buffer().","modified":"2026-09-15T09:02:50.914892813Z","published":"2025-09-16T17:15:38.050Z","upstream":["CVE-2023-53320"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53320"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53320.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53320.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53320.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}