cbcvebase.
CVE-2023-53299
published 2025-09-16

CVE-2023-53299: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix leak of 'r10bio->remaining' for recovery raid10_sync_request() will add…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix leak of 'r10bio->remaining' for recovery raid10_sync_request() will add 'r10bio->remaining' for both rdev and replacement rdev. However, if the read io fails, recovery_request_write() returns without issuing the write io, in this case, end_sync_request() is only called once and 'remaining' is leaked, cause an io hang. Fix the problem by decreasing 'remaining' according to if 'bio' and 'repl_bio' is valid.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < cb827ed2bb34480dc102146d3a1f89fdbcafc028cb827ed2bb34480dc102146d3a1f89fdbcafc028
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 1d2c6c6e37fe5de11fd01a82badf03390e12df7a1d2c6c6e37fe5de11fd01a82badf03390e12df7a
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 8c5d5d7ffd1e76734811b8ea5417cf0432b9952c8c5d5d7ffd1e76734811b8ea5417cf0432b9952c
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 1697fb124c6d6c5237e9cbd788903101547380841697fb124c6d6c5237e9cbd78890310154738084
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 8d09065802c53cc938d162b62f6c4150b392c90e8d09065802c53cc938d162b62f6c4150b392c90e
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 11141630f03efffdfe260b3582b2d93d38171b9711141630f03efffdfe260b3582b2d93d38171b97
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 3481dec5ecbbbbe44ab23e22c2b14bd65c644ec63481dec5ecbbbbe44ab23e22c2b14bd65c644ec6
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 4f82e7e07cdaf2947d71968e3d6b73370a2170934f82e7e07cdaf2947d71968e3d6b73370a217093
linuxlinux>= 24afd80d99f80a79d8824d2805114b8b067e9823 < 26208a7cffd0c7cbf14237ccd20c7270b3ffeb7e26208a7cffd0c7cbf14237ccd20c7270b3ffeb7e
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 3.3 < 4.14.3154.14.315
linuxlinux_kernel>= 4.15 < 4.19.2834.19.283
linuxlinux_kernel>= 4.20 < 5.4.2435.4.243
linuxlinux_kernel>= 5.11 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16 < 6.1.286.1.28
linuxlinux_kernel>= 5.5 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2 < 6.2.156.2.15
linuxlinux_kernel>= 6.3 < 6.3.26.3.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.