cbcvebase.
CVE-2023-53622
published 2025-10-07

CVE-2023-53622: In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix possible data races in gfs2_show_options() Some fields such as gt_logd_secs of…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix possible data races in gfs2_show_options() Some fields such as gt_logd_secs of the struct gfs2_tune are accessed without holding the lock gt_spin in gfs2_show_options(): val = sdp->sd_tune.gt_logd_secs; if (val != 30) seq_printf(s, ",commit=%d", val); And thus can cause data races when gfs2_show_options() and other functions such as gfs2_reconfigure() are concurrently executed: spin_lock(>->gt_spin); gt->gt_logd_secs = newargs->ar_commit; To fix these possible data races, the lock sdp->sd_tune.gt_spin is acquired before accessing the fields of gfs2_tune and released after these accesses. Further changes by Andreas: - Don't hold the spin lock over the seq_printf operations.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 7e5bbeb7eb813bb2568e1d5d02587df943272e577e5bbeb7eb813bb2568e1d5d02587df943272e57
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 235a5ae73cea29109a3e06f100493f17857e6a93235a5ae73cea29109a3e06f100493f17857e6a93
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < b4a7ab57effbed42624842f2ab2a49b177c21a47b4a7ab57effbed42624842f2ab2a49b177c21a47
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 7c5b2649f6a37d45bfb7abf34c9b71d08677139f7c5b2649f6a37d45bfb7abf34c9b71d08677139f
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 85e888150075cb221270b64bf772341fc6bd11d985e888150075cb221270b64bf772341fc6bd11d9
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < a4f71523ed2123d63b431cc0cea4e9f363a0f054a4f71523ed2123d63b431cc0cea4e9f363a0f054
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 42077d4de49e4d9c773c97c42d5383b4899a8f9d42077d4de49e4d9c773c97c42d5383b4899a8f9d
linuxlinux>= 48c2b613616235d7c97fda5982f50100a6c79166 < 6fa0a72cbbe45db4ed967a51f9e6f4e3afe61d206fa0a72cbbe45db4ed967a51f9e6f4e3afe61d20
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 2.6.31 < 4.14.3244.14.324
linuxlinux_kernel>= 4.15 < 4.19.2934.19.293
linuxlinux_kernel>= 4.20 < 5.4.2555.4.255
linuxlinux_kernel>= 5.11 < 5.15.1285.15.128
linuxlinux_kernel>= 5.16 < 6.1.476.1.47
linuxlinux_kernel>= 5.5 < 5.10.1925.10.192
linuxlinux_kernel>= 6.2 < 6.4.126.4.12

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.