CVE-2023-53360 Details
Description
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.
A vulnerability in the Linux kernel's NFSv4.2 implementation can lead to a double-free error in the scratch buffer used for read operations. This issue arises because the read code can send multiple requests with the same nfs_pgio_header, while the setup function is only called once. As a result, the scratch buffer may be double-freed or, conversely, a NULL pointer with a non-zero length can be sent to the xdr scratch buffer. This discrepancy causes a kernel oops the first time decoding attempts to write to the scratch buffer, a common occurrence when handling READ_PLUS hole segments. The vulnerability affects several versions of the Linux kernel.
Users can upgrade to the patched version of the Linux kernel, which is available in the Linux kernel stable tree. Instructions for downloading the updated kernel can be found in the Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/303a78052091c81e9003915c521fdca1c7e117af | kernel.org | Patch |
| https://git.kernel.org/stable/c/a2f4cb206bd94b3f4a7bb05fcdce9525283b5681 | kernel.org | Patch |
| https://git.kernel.org/stable/c/adac9f0ddd2b291c7ce41f549fdb27a13616cff5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ae5d5672f1db711e91db6f52df5cb16ecd8f5692 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | [email protected] |
| CWE-415 | Double Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.4, < 6.4.16 >= 6.5, < 6.5.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | CVE Modified | CISA-ADP |
| Dec 11, 2025 | Initial Analysis | [email protected] |
| Sep 17, 2025 | New CVE Received | kernel.org |