CVE-2023-53339Reachable Assertion in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix BUG_ON condition in btrfs_cancel_balance Pausing and canceling balance can race to interrupt balance lead to BUG_ON panic in btrfs_cancel_balance. The BUG_ON condition in btrfs_cancel_balance does not take this race scenario into account. However, the race condition has no other side effects. We can fix that. Reproducing it with panic trace like this: kernel BUG at fs/btrfs/volumes.c:4618! RIP: 0010:btrfs_cancel_

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.205.4.255+6
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linuxddf7e8984c83aee9122552529f4e77291903f8d9ceb9ba8e30833a4823e2dc73f80ebcdf2498d01a+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7gmh-9h47-r2x3: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix BUG_ON condition in btrfs_cancel_balance Pausing and canceling balanc2025-09-17
OSV
CVE-2023-53339: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix BUG_ON condition in btrfs_cancel_balance Pausing and canceling balance2025-09-17

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service in btrfs due to race condition2025-09-17
Debian
CVE-2023-53339: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ...2023
CVE-2023-53339 — Reachable Assertion in Linux | cvebase