CVE-2023-53348Improper Locking in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock when aborting transaction during relocation with scrub Before relocating a block group we pause scrub, then do the relocation and then unpause scrub. The relocation process requires starting and committing a transaction, and if we have a failure in the critical section of the transaction commit path (transaction state >= TRANS_STATE_COMMIT_START), we will deadlock if there is a paused scrub. That results i

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel4.36.1.23+2
Debianlinux/linux_kernel< 6.1.25-1+2
CVEListV5linux/linux55e3a601c81cdca4497bf855fa4d331f8e8307446134a4bb6b1c411a244edee041ac89266c78d45c+3
debiandebian/linux< linux 6.1.25-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53348: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock when aborting transaction during relocation with scrub Before2025-09-17
GHSA
GHSA-vmvh-gj86-w48f: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock when aborting transaction during relocation with scrub Befor2025-09-17

📋Vendor Advisories

3
Red Hat
kernel: Kernel: Denial of Service due to deadlock in btrfs during block group relocation with scrub2025-09-17
Microsoft
btrfs: fix deadlock when aborting transaction during relocation with scrub2025-09-09
Debian
CVE-2023-53348: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: fix ...2023
CVE-2023-53348 — Improper Locking in Linux | cvebase