cbcvebase.
CVE-2023-53149
published 2025-09-15

CVE-2023-53149: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid deadlock in fs reclaim with page writeback Ext4 has a filesystem wide lock…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid deadlock in fs reclaim with page writeback Ext4 has a filesystem wide lock protecting ext4_writepages() calls to avoid races with switching of journalled data flag or inode format. This lock can however cause a deadlock like: CPU0 CPU1 ext4_writepages() percpu_down_read(sbi->s_writepages_rwsem); ext4_change_inode_journal_flag() percpu_down_write(sbi->s_writepages_rwsem); - blocks, all readers block from now on ext4_do_writepages() ext4_init_io_end() kmem_cache_zalloc(io_end_cachep, GFP_KERNEL) fs_reclaim frees dentry... dentry_unlink_inode() iput() - last ref => iput_final() - inode dirty => write_inode_now()... ext4_writepages() tries to acquire sbi->s_writepages_rwsem and blocks forever Make sure we cannot recurse into filesystem reclaim from writeback code to avoid the deadlock.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.3.7-1 (forky)linux 6.3.7-1 (forky)
linuxlinux
linuxlinux>= c8585c6fcaf2011de54c3592e80a634a2b9e1a7f < 2ec97dc90df40c50e509809dc9a198638a7e18b62ec97dc90df40c50e509809dc9a198638a7e18b6
linuxlinux>= c8585c6fcaf2011de54c3592e80a634a2b9e1a7f < 4b4340bf04ce9a52061f15000ecedd126abc093c4b4340bf04ce9a52061f15000ecedd126abc093c
linuxlinux>= c8585c6fcaf2011de54c3592e80a634a2b9e1a7f < 00d873c17e29cc32d90ca852b82685f1673acaa500d873c17e29cc32d90ca852b82685f1673acaa5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.7 < 6.2.166.2.16
linuxlinux_kernel>= 6.3 < 6.3.36.3.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.