CVE-2023-53380
published 2025-09-18CVE-2023-53380: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request There are two check of…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
There are two check of 'mreplace' in raid10_sync_request(). In the first
check, 'need_replace' will be set and 'mreplace' will be used later if
no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be
set to NULL if it is Faulty, but 'need_replace' will not be changed
accordingly. null-ptr-deref occurs if Faulty is set between two check.
Fix it by merging two checks into one. And replace 'need_replace' with
'mreplace' because their values are always the same.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < 45fa023b3334a7ae6f6c4eb977295804222dfa28 | 45fa023b3334a7ae6f6c4eb977295804222dfa28 |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < 2990e2ece18dd4cca71b3109c80517ad94adb065 | 2990e2ece18dd4cca71b3109c80517ad94adb065 |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < f4368a462b1f9a8ecc2fdb09a28c3d4cad302a4f | f4368a462b1f9a8ecc2fdb09a28c3d4cad302a4f |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < 222cc459d59857ee28a5366dc225ab42b22f9272 | 222cc459d59857ee28a5366dc225ab42b22f9272 |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < b5015b97adda6a24dd3e713c63e521ecbeff25c6 | b5015b97adda6a24dd3e713c63e521ecbeff25c6 |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < 144c7fd008e0072b0b565f1157eec618de54ca8a | 144c7fd008e0072b0b565f1157eec618de54ca8a |
| linux | linux | >= ee37d7314a32ab6809eacc3389bad0406c69a81f < 34817a2441747b48e444cb0e05d84e14bc9443da | 34817a2441747b48e444cb0e05d84e14bc9443da |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 4.20 < 5.4.251 | 5.4.251 |
| linux | linux_kernel | >= 5.11 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16 < 6.1.39 | 6.1.39 |
| linux | linux_kernel | >= 5.5 < 5.10.188 | 5.10.188 |
| linux | linux_kernel | >= 6.2 < 6.3.13 | 6.3.13 |
| linux | linux_kernel | >= 6.4 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
vendor_redhat·2025-09-18·CVSS 5.5
CVE-2023-53380 [MEDIUM] CWE-476 kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
kernel: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
There are two check of 'mreplace' in raid10_sync_request(). In the first
check, 'need_replace' will be set and 'mreplace' will be used later if
no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be
set to NULL if it is Faulty, but 'need_replace' will not be changed
accordingly. null-ptr-deref occurs if Faulty is set between two check.
Fix it by merging two checks into one. And replace 'need_replace' with
'mreplace' because their values are always the same.
Statement: The bug is a race in raid10_sync_request() where mreplace could become Faulty between two checks, leaving
Debian
CVE-2023-53380: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
vendor_debian·2023·CVSS 5.5
CVE-2023-53380 [MEDIUM] CVE-2023-53380: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request There are two check of 'mreplace' in raid10_sync_request(). In the first check, 'need_replace' will be set and 'mreplace' will be used later if no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be set to NULL if it is Faulty, but 'need_replace' will not be changed accordingly. null-ptr-deref occurs if Faulty is set between two check. Fix it by merging two checks into one. And replace 'need_replace' with 'mreplace' because their values are always the same.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.4-1)
sid: resolved (fixed in 6.4.4-1)
trixie: resolved (fixed in 6.4
GHSA
GHSA-9g3f-fgm8-4cgm: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
There are two c
ghsa_unreviewed·2025-09-18
CVE-2023-53380 [MEDIUM] CWE-476 GHSA-9g3f-fgm8-4cgm: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
There are two c
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request
There are two check of 'mreplace' in raid10_sync_request(). In the first
check, 'need_replace' will be set and 'mreplace' will be used later if
no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be
set to NULL if it is Faulty, but 'need_replace' will not be changed
accordingly. null-ptr-deref occurs if Faulty is set between two check.
Fix it by merging two checks into one. And replace 'need_replace' with
'mreplace' because their values are always the same.
OSV
CVE-2023-53380: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request There are two che
osv·2025-09-18·CVSS 5.5
CVE-2023-53380 [MEDIUM] CVE-2023-53380: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request There are two che
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request There are two check of 'mreplace' in raid10_sync_request(). In the first check, 'need_replace' will be set and 'mreplace' will be used later if no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be set to NULL if it is Faulty, but 'need_replace' will not be changed accordingly. null-ptr-deref occurs if Faulty is set between two check. Fix it by merging two checks into one. And replace 'need_replace' with 'mreplace' because their values are always the same.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/144c7fd008e0072b0b565f1157eec618de54ca8ahttps://git.kernel.org/stable/c/222cc459d59857ee28a5366dc225ab42b22f9272https://git.kernel.org/stable/c/2990e2ece18dd4cca71b3109c80517ad94adb065https://git.kernel.org/stable/c/34817a2441747b48e444cb0e05d84e14bc9443dahttps://git.kernel.org/stable/c/45fa023b3334a7ae6f6c4eb977295804222dfa28https://git.kernel.org/stable/c/b5015b97adda6a24dd3e713c63e521ecbeff25c6https://git.kernel.org/stable/c/f4368a462b1f9a8ecc2fdb09a28c3d4cad302a4f
2025-09-18
Published