CVE-2023-53777Deadlock in Linux

CWE-833Deadlock6 documents5 sources
Severity
4.7MEDIUM
No vector
EPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: erofs: kill hooked chains to avoid loops on deduplicated compressed images After heavily stressing EROFS with several images which include a hand-crafted image of repeated patterns for more than 46 days, I found two chains could be linked with each other almost simultaneously and form a loop so that the entire loop won't be submitted. As a consequence, the corresponding file pages will remain locked forever. It can be _only_

Affected Packages4 packages

Linuxlinux/linux_kernel6.0.06.1.39+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linux267f2492c8f71dac44399988b510f9bf6b074a51d3b39ea24835ac03da1a30f93ae7c05d55a40191+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
erofs: kill hooked chains to avoid loops on deduplicated compressed images2025-12-09
OSV
CVE-2023-53777: In the Linux kernel, the following vulnerability has been resolved: erofs: kill hooked chains to avoid loops on deduplicated compressed images After h2025-12-09
GHSA
GHSA-v9mq-q8m3-5r3r: In the Linux kernel, the following vulnerability has been resolved: erofs: kill hooked chains to avoid loops on deduplicated compressed images After2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: erofs: kill hooked chains to avoid loops on deduplicated compressed images2025-12-09
Debian
CVE-2023-53777: linux - In the Linux kernel, the following vulnerability has been resolved: erofs: kill...2023