cbcvebase.
CVE-2023-53608
published 2025-10-04

CVE-2023-53608: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread() The finalization of nilfs_segctor_thread() can race with nilfs_segctor_kill_thread() which terminates that thread, potentially causing a use-after-free BUG as KASAN detected. At the end of nilfs_segctor_thread(), it assigns NULL to "sc_task" member of "struct nilfs_sc_info" to indicate the thread has finished, and then notifies nilfs_segctor_kill_thread() of this using waitqueue "sc_wait_task" on the struct nilfs_sc_info. However, here, immediately after the NULL assignment to "sc_task", it is possible that nilfs_segctor_kill_thread() will detect it and return to continue the deallocation, freeing the nilfs_sc_info structure before the thread does the notification. This fixes the issue by protecting the NULL assignment to "sc_task" and its notification, with spinlock "sc_state_lock" of the struct nilfs_sc_info. Since nilfs_segctor_kill_thread() does a final check to see if "sc_task" is NULL with "sc_state_lock" locked, this can eliminate the race.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 034cce77d52ba013ce62b4f5258c29907eb1ada5034cce77d52ba013ce62b4f5258c29907eb1ada5
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcc0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcc
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 613bf23c070d11c525268f2945aa594704a9b764613bf23c070d11c525268f2945aa594704a9b764
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < f32297dba338dc06d62286dedb3cdbd5175b1719f32297dba338dc06d62286dedb3cdbd5175b1719
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 92684e02654c91a61a0b0561433b710bcece19fe92684e02654c91a61a0b0561433b710bcece19fe
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < bae009a2f1b7c2011d2e92d8c84868d315c0b97ebae009a2f1b7c2011d2e92d8c84868d315c0b97e
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < b4d80bd6370b81a1725b6b8f7894802c23a14e9fb4d80bd6370b81a1725b6b8f7894802c23a14e9f
linuxlinux>= 9ff05123e3bfbb1d2b68ba1d9bf1f7d1dffc1453 < 6be49d100c22ffea3287a4b19d7639d259888e336be49d100c22ffea3287a4b19d7639d259888e33
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 2.6.30 < 4.14.3134.14.313
linuxlinux_kernel>= 4.15 < 4.19.2814.19.281
linuxlinux_kernel>= 4.20 < 5.4.2415.4.241
linuxlinux_kernel>= 5.11 < 5.15.1075.15.107
linuxlinux_kernel>= 5.16 < 6.1.246.1.24
linuxlinux_kernel>= 5.5 < 5.10.1785.10.178
linuxlinux_kernel>= 6.2 < 6.2.116.2.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.