Linux Kernel SCSI SES Driver Enclosure Component Validation Issue

Vulnerability

A vulnerability in the Linux kernel's SCSI SES driver has been addressed. The issue arose when the driver attempted to manage enclosures lacking components, which could lead to a system error. The driver will now correctly identify and skip such enclosures, preventing potential errors.

Impact

The vulnerability could cause a system error if the driver tried to manage an enclosure with no components.

Reproduction

The vulnerability can be reproduced by connecting a SCSI enclosure that has no components to a system running the affected Linux kernel version. The SCSI SES driver will attempt to manage the enclosure, leading to a system error.

Remediation

Users can upgrade to the latest version of the Linux kernel where this issue has been fixed.

Added: Sep 18, 2025, 4:58 PM
Updated: Sep 18, 2025, 4:58 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.3
remediation
7.7
relevance
0.5
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.