---
id: CVE-2023-52515
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/srp: Do not call scsi_done() from srp_abort()

  After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler
  callback, it performs one of the following ac…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  RDMA/srp: Do not call scsi_done() from srp_abort()

  After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler
  callback, it performs one of the following ac…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 3.7, < 5.10.199'
  - 'linux_kernel >= 5.11, < 5.15.136'
  - 'linux_kernel >= 5.16, < 6.1.57'
  - 'linux_kernel >= 6.2, < 6.5.7'
  - linux_kernel = 6.6
patched:
  - linux_kernel 6.5.7
published: '2024-03-02'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52515'
references:
  - url: 'https://git.kernel.org/stable/c/05a10b316adaac1f322007ca9a0383b410d759cc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/26788a5b48d9d5cd3283d777d238631c8cd7495a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2b298f9181582270d5e95774e5a6c7a7fb5b1206'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b9bdffb3f9aaeff8379c83f5449c6b42cb71c2b5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e193b7955dfad68035b983a0011f4ef3590c85eb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/05a10b316adaac1f322007ca9a0383b410d759cc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/26788a5b48d9d5cd3283d777d238631c8cd7495a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/2b298f9181582270d5e95774e5a6c7a7fb5b1206'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/b9bdffb3f9aaeff8379c83f5449c6b42cb71c2b5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e193b7955dfad68035b983a0011f4ef3590c85eb'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00613
epssPercentile: 0.47144
ingestedAt: '2026-08-04T10:39:40.099Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

RDMA/srp: Do not call scsi_done() from srp_abort()

After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler
callback, it performs one of the following actions:
* Call scsi_queue_insert().
* Call scsi_finish_command().
* Call scsi_eh_scmd_add().
Hence, SCSI abort handlers must not call scsi_done(). Otherwise all
the above actions would trigger a use-after-free. Hence remove the
scsi_done() call from srp_abort(). Keep the srp_free_req() call
before returning SUCCESS because we may not see the command again if
SUCCESS is returned.

## Affected

- `linux_kernel >= 3.7, < 5.10.199`
- `linux_kernel >= 5.11, < 5.15.136`
- `linux_kernel >= 5.16, < 6.1.57`
- `linux_kernel >= 6.2, < 6.5.7`
- `linux_kernel = 6.6`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.5.7`
