CVE-2023-53608
published 2025-10-04CVE-2023-53608: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
The finalization of nilfs_segctor_thread() can race with
nilfs_segctor_kill_thread() which terminates that thread, potentially
causing a use-after-free BUG as KASAN detected.
At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member
of "struct nilfs_sc_info" to indicate the thread has finished, and then
notifies nilfs_segctor_kill_thread() of this using waitqueue
"sc_wait_task" on the struct nilfs_sc_info.
However, here, immediately after the NULL assignment to "sc_task", it is
possible that nilfs_segctor_kill_thread() will detect it and return to
continue the deallocation, freeing the nilfs_sc_info structure before the
thread does the notification.
This fixes the issue by protecting the NULL assignment to "sc_task" and
its notification, with spinlock "sc_state_lock" of the struct
nilfs_sc_info. Since nilfs_segctor_kill_thread() does a final check to
see if "sc_task" is NULL with "sc_state_lock" locked, this can eliminate
the race.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 034cce77d52ba013ce62b4f5258c29907eb1ada5 | 034cce77d52ba013ce62b4f5258c29907eb1ada5 |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcc | 0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcc |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 613bf23c070d11c525268f2945aa594704a9b764 | 613bf23c070d11c525268f2945aa594704a9b764 |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < f32297dba338dc06d62286dedb3cdbd5175b1719 | f32297dba338dc06d62286dedb3cdbd5175b1719 |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 92684e02654c91a61a0b0561433b710bcece19fe | 92684e02654c91a61a0b0561433b710bcece19fe |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < bae009a2f1b7c2011d2e92d8c84868d315c0b97e | bae009a2f1b7c2011d2e92d8c84868d315c0b97e |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < b4d80bd6370b81a1725b6b8f7894802c23a14e9f | b4d80bd6370b81a1725b6b8f7894802c23a14e9f |
| linux | linux | >= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 6be49d100c22ffea3287a4b19d7639d259888e33 | 6be49d100c22ffea3287a4b19d7639d259888e33 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 2.6.30 < 4.14.313 | 4.14.313 |
| linux | linux_kernel | >= 4.15 < 4.19.281 | 4.19.281 |
| linux | linux_kernel | >= 4.20 < 5.4.241 | 5.4.241 |
| linux | linux_kernel | >= 5.11 < 5.15.107 | 5.15.107 |
| linux | linux_kernel | >= 5.16 < 6.1.24 | 6.1.24 |
| linux | linux_kernel | >= 5.5 < 5.10.178 | 5.10.178 |
| linux | linux_kernel | >= 6.2 < 6.2.11 | 6.2.11 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
vendor_redhat·2025-10-04·CVSS 7.8
CVE-2023-53608 [HIGH] kernel: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
kernel: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
The finalization of nilfs_segctor_thread() can race with
nilfs_segctor_kill_thread() which terminates that thread, potentially
causing a use-after-free BUG as KASAN detected.
At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member
of "struct nilfs_sc_info" to indicate the thread has finished, and then
notifies nilfs_segctor_kill_thread() of this using waitqueue
"sc_wait_task" on the struct nilfs_sc_info.
However, here, immediately after the NULL assignment to "sc_task", it is
possible that nilfs_segctor_kill_thread() will detect it and return to
c
Debian
CVE-2023-53608: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
vendor_debian·2023·CVSS 7.8
CVE-2023-53608 [HIGH] CVE-2023-53608: linux - In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix...
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The finalization of nilfs_segctor_thread() can race with nilfs_segctor_kill_thread() which terminates that thread, potentially causing a use-after-free BUG as KASAN detected. At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member of "struct nilfs_sc_info" to indicate the thread has finished, and then notifies nilfs_segctor_kill_thread() of this using waitqueue "sc_wait_task" on the struct nilfs_sc_info. However, here, immediately after the NULL assignment to "sc_task", it is possible that nilfs_segctor_kill_thread() will detect it and return to continue the deallocation, freeing the nilfs_sc_info structure before the thread does
VulDB
Linux Kernel up to 6.2.10 nilfs2 nilfs_segctor_thread use after free (EUVD-2023-60000 / WID-SEC-2025-2194)
vuldb·2026-04-28·CVSS 7.8
CVE-2023-53608 [HIGH] Linux Kernel up to 6.2.10 nilfs2 nilfs_segctor_thread use after free (EUVD-2023-60000 / WID-SEC-2025-2194)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.2.10. This vulnerability affects the function nilfs_segctor_thread of the component nilfs2. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2023-53608. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
OSV
CVE-2023-53608: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The fi
osv·2025-10-04·CVSS 7.8
CVE-2023-53608 [HIGH] CVE-2023-53608: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The fi
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The finalization of nilfs_segctor_thread() can race with nilfs_segctor_kill_thread() which terminates that thread, potentially causing a use-after-free BUG as KASAN detected. At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member of "struct nilfs_sc_info" to indicate the thread has finished, and then notifies nilfs_segctor_kill_thread() of this using waitqueue "sc_wait_task" on the struct nilfs_sc_info. However, here, immediately after the NULL assignment to "sc_task", it is possible that nilfs_segctor_kill_thread() will detect it and return to continue the deallocation, freeing the nilfs_sc_info structure before the thread does
GHSA
GHSA-g3qq-fg79-63v4: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
The
ghsa_unreviewed·2025-10-04
CVE-2023-53608 [HIGH] CWE-416 GHSA-g3qq-fg79-63v4: In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
The
In the Linux kernel, the following vulnerability has been resolved:
nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()
The finalization of nilfs_segctor_thread() can race with
nilfs_segctor_kill_thread() which terminates that thread, potentially
causing a use-after-free BUG as KASAN detected.
At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member
of "struct nilfs_sc_info" to indicate the thread has finished, and then
notifies nilfs_segctor_kill_thread() of this using waitqueue
"sc_wait_task" on the struct nilfs_sc_info.
However, here, immediately after the NULL assignment to "sc_task", it is
possible that nilfs_segctor_kill_thread() will detect it and return to
continue the deallocation, freeing the nilfs_sc_info structure before the
thread d
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/034cce77d52ba013ce62b4f5258c29907eb1ada5https://git.kernel.org/stable/c/0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcchttps://git.kernel.org/stable/c/613bf23c070d11c525268f2945aa594704a9b764https://git.kernel.org/stable/c/6be49d100c22ffea3287a4b19d7639d259888e33https://git.kernel.org/stable/c/92684e02654c91a61a0b0561433b710bcece19fehttps://git.kernel.org/stable/c/b4d80bd6370b81a1725b6b8f7894802c23a14e9fhttps://git.kernel.org/stable/c/bae009a2f1b7c2011d2e92d8c84868d315c0b97ehttps://git.kernel.org/stable/c/f32297dba338dc06d62286dedb3cdbd5175b1719
2025-10-04
Published