CVE-2023-53360
published 2025-09-17CVE-2023-53360: In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.37%
30.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: Rework scratch handling for READ_PLUS (again)
I found that the read code might send multiple requests using the same
nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is
how we ended up occasionally double-freeing the scratch buffer, but also
means we set a NULL pointer but non-zero length to the xdr scratch
buffer. This results in an oops the first time decoding needs to copy
something to scratch, which frequently happens when decoding READ_PLUS
hole segments.
I fix this by moving scratch handling into the pageio read code. I
provide a function to allocate scratch space for decoding read replies,
and free the scratch buffer when the nfs_pgio_header is freed.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 886959f425b6a936a30b82a297ae3aecb3b8230f < adac9f0ddd2b291c7ce41f549fdb27a13616cff5 | adac9f0ddd2b291c7ce41f549fdb27a13616cff5 |
| linux | linux | >= fbd2a05f29a95d5b42b294bf47e55a711424965b < a2f4cb206bd94b3f4a7bb05fcdce9525283b5681 | a2f4cb206bd94b3f4a7bb05fcdce9525283b5681 |
| linux | linux | >= fbd2a05f29a95d5b42b294bf47e55a711424965b < ae5d5672f1db711e91db6f52df5cb16ecd8f5692 | ae5d5672f1db711e91db6f52df5cb16ecd8f5692 |
| linux | linux | >= fbd2a05f29a95d5b42b294bf47e55a711424965b < 303a78052091c81e9003915c521fdca1c7e117af | 303a78052091c81e9003915c521fdca1c7e117af |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 6.4 < 6.4.16 | 6.4.16 |
| linux | linux_kernel | >= 6.5 < 6.5.3 | 6.5.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: NFSv4.2: Rework scratch handling for READ_PLUS (again)
vendor_redhat·2025-09-17·CVSS 5.5
CVE-2023-53360 [MEDIUM] CWE-415 kernel: NFSv4.2: Rework scratch handling for READ_PLUS (again)
kernel: NFSv4.2: Rework scratch handling for READ_PLUS (again)
In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: Rework scratch handling for READ_PLUS (again)
I found that the read code might send multiple requests using the same
nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is
how we ended up occasionally double-freeing the scratch buffer, but also
means we set a NULL pointer but non-zero length to the xdr scratch
buffer. This results in an oops the first time decoding needs to copy
something to scratch, which frequently happens when decoding READ_PLUS
hole segments.
I fix this by moving scratch handling into the pageio read code. I
provide a function to allocate scratch space for decoding read replies,
and free the scratch buffer when t
Debian
CVE-2023-53360: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Re...
vendor_debian·2023·CVSS 5.5
CVE-2023-53360 [MEDIUM] CVE-2023-53360: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Re...
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.
Scope: local
bookworm: resolved (fi
OSV
CVE-2023-53360: In the Linux kernel, the following vulnerability has been resolved: NFSv4
osv·2025-09-17·CVSS 5.5
CVE-2023-53360 [MEDIUM] CVE-2023-53360: In the Linux kernel, the following vulnerability has been resolved: NFSv4
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.
GHSA
GHSA-4v4w-685q-cqmx: In the Linux kernel, the following vulnerability has been resolved:
NFSv4
ghsa_unreviewed·2025-09-17
CVE-2023-53360 [MEDIUM] CWE-415 GHSA-4v4w-685q-cqmx: In the Linux kernel, the following vulnerability has been resolved:
NFSv4
In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: Rework scratch handling for READ_PLUS (again)
I found that the read code might send multiple requests using the same
nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is
how we ended up occasionally double-freeing the scratch buffer, but also
means we set a NULL pointer but non-zero length to the xdr scratch
buffer. This results in an oops the first time decoding needs to copy
something to scratch, which frequently happens when decoding READ_PLUS
hole segments.
I fix this by moving scratch handling into the pageio read code. I
provide a function to allocate scratch space for decoding read replies,
and free the scratch buffer when the nfs_pgio_header is freed.
No detection rules found.
No public exploits indexed.
2025-09-17
Published