cbcvebase.
CVE-2026-23053
published 2026-02-04

CVE-2026-23053: In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a deadlock involving nfs_release_folio() Wang Zhaolong reports a deadlock…

PriorityP418high7.8
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a deadlock involving nfs_release_folio() Wang Zhaolong reports a deadlock involving NFSv4.1 state recovery waiting on kthreadd, which is attempting to reclaim memory by calling nfs_release_folio(). The latter cannot make progress due to state recovery being needed. It seems that the only safe thing to do here is to kick off a writeback of the folio, without waiting for completion, or else kicking off an asynchronous commit.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= 96780ca55e3cbf4f150fd5a833a61492c9947b5b < a4810f8beb0122f032f10735f98d257aa6064f4ca4810f8beb0122f032f10735f98d257aa6064f4c
linuxlinux>= 96780ca55e3cbf4f150fd5a833a61492c9947b5b < 49d352bc263fe4a834233338bfaad31b3109addf49d352bc263fe4a834233338bfaad31b3109addf
linuxlinux>= 96780ca55e3cbf4f150fd5a833a61492c9947b5b < 19b4d9ab5e77843eac0429c019470c02f8710b5519b4d9ab5e77843eac0429c019470c02f8710b55
linuxlinux>= 96780ca55e3cbf4f150fd5a833a61492c9947b5b < cce0be6eb4971456b703aaeafd571650d314bccacce0be6eb4971456b703aaeafd571650d314bcca
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.3.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.