CVE-2023-53990Improper Resource Locking in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: SMB3: Add missing locks to protect deferred close file list cifs_del_deferred_close function has a critical section which modifies the deferred close file list. We must acquire deferred_lock before calling cifs_del_deferred_close function.

Affected Packages4 packages

Linuxlinux/linux_kernel5.16.06.1.28+3
Debianlinux/linux_kernel< 6.1.37-1+2
CVEListV5linux/linux860efae127888ae535bc4eda1b7f27642727c69e0f87e18203bd30f71eb1a65259e28e291b6cc43a+6
debiandebian/linux< linux 6.1.37-1 (bookworm)

🔴Vulnerability Details

3
OSV
SMB3: Add missing locks to protect deferred close file list2025-12-24
GHSA
GHSA-8hvc-93qx-9q29: In the Linux kernel, the following vulnerability has been resolved: SMB3: Add missing locks to protect deferred close file list cifs_del_deferred_cl2025-12-24
OSV
CVE-2023-53990: In the Linux kernel, the following vulnerability has been resolved: SMB3: Add missing locks to protect deferred close file list cifs_del_deferred_clos2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: SMB3: Add missing locks to protect deferred close file list2025-12-24
Debian
CVE-2023-53990: linux - In the Linux kernel, the following vulnerability has been resolved: SMB3: Add m...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-53990 Impact, Exploitability, and Mitigation Steps | Wiz