CVE-2023-53440NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current nilfs2 sysfs support has issues with the timing of creation and deletion of sysfs entries, potentially leading to null pointer dereferences, use-after-free, and lockdep warnings. Some of the sysfs attributes for nilfs2 per-filesystem instance refer to metadata file "cpfile", "sufile", or "dat", but nilfs_sysfs_create_device_group that creates those attributes is executed before

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel3.174.14.313+7
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxdd70edbde2627f47df118d899de6bbb55abcfdbfd20dcec8f326deb77b6688f8441e014045dac457+8
debiandebian/linux< linux 6.1.25-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53440: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current nilfs2 sysfs support has issues w2025-09-18
GHSA
GHSA-v99g-2hwc-34c3: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current nilfs2 sysfs support has issues2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: nilfs2: fix sysfs interface lifetime2025-09-18
Debian
CVE-2023-53440: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...2023
CVE-2023-53440 — NULL Pointer Dereference in Linux | cvebase