CVE-2023-53481Infinite Loop in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1

Description

In the Linux kernel, the following vulnerability has been resolved: ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed Following process will trigger an infinite loop in ubi_wl_put_peb(): ubifs_bgt ubi_bgt ubifs_leb_unmap ubi_leb_unmap ubi_eba_unmap_leb ubi_wl_put_peb wear_leveling_worker e1 = rb_entry(rb_first(&ubi->used) e2 = get_peb_for_wl(ubi) ubi_io_read_vid_hdr // return err (flash fault) out_error: ubi->move_from = ubi->move_to = NULL wl_entry_destroy(ubi, e1) ubi->l

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel2.6.254.14.308+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux43f9b25a9cdd7b177f77f026b1461abd1abbd174b40d2fbf47af58377e898b5062077a47bb28a132+8
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53481: In the Linux kernel, the following vulnerability has been resolved: ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed Following pr2025-10-01
GHSA
GHSA-3pv3-rmr2-25g2: In the Linux kernel, the following vulnerability has been resolved: ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed Following2025-10-01

📋Vendor Advisories

2
Red Hat
kernel: ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed2025-10-01
Debian
CVE-2023-53481: linux - In the Linux kernel, the following vulnerability has been resolved: ubi: ubi_wl...2023