Red Hat has detailed CVE-2023-53675, a moderate-severity out-of-bounds read in the Linux kernel's SCSI Enclosure Services (SES) driver. The flaw arises because ses_enclosure_data_process() does not adequately validate descriptor-pointer positions while parsing enclosure data, allowing malformed enclosure pages to trigger reads beyond the intended buffer.
A local low-privileged user could exploit the issue to crash an affected system during enclosure-data processing, resulting in denial of service; Red Hat's assessment also notes possible confidentiality and integrity effects. Kernel fixes are available for affected Red Hat Enterprise Linux 7 and 8 support streams, while organizations unable to patch immediately can mitigate exposure by preventing the ses kernel module from loading.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:0754 and RHSA-2026:0755, providing fixed kernel-rt and kernel packages for Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Red Hat issued RHSA-2026:0643 with a fixed kernel package for Red Hat Enterprise Linux 8.2 Advanced Update Support.
Red Hat issued RHSA-2026:0532, RHSA-2026:0533, and RHSA-2026:0536, providing fixed kernel packages for affected RHEL 8.4, 8.6, and 8.8 specialized support streams.
Red Hat published its record for CVE-2023-53675, describing an out-of-bounds read in the Linux kernel SES driver that a low-privileged local user could trigger to cause a denial of service.
Red Hat issued RHSA-2023:7077 with fixed kernel packages for Red Hat Enterprise Linux 8 support streams, addressing the SES-driver out-of-bounds read vulnerability.
The Linux kernel CVE team identified possible desc_ptr out-of-bounds accesses in the SES driver's ses_enclosure_data_process() function and documented remediation commits across stable kernel releases 4.14.308 through 6.3. It recommended updating to a current stable kernel release rather than applying individual commits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.