PT-2025-18847 · Linux+3 · Linux Kernel+3
Published
2023-03-30
·
Updated
2026-01-28
·
CVE-2023-53083
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been identified, related to the nfsd splice actor function. The issue arises when the splice read calls nfsd splice actor to put pages containing file data into the svc rqst->rq pages array. If a partial page is received at the end of the splice result, it can be added to the array multiple times, potentially corrupting the reply and overrunning the array. This can lead to corruption of the trailing fields, including the rq respages and rq next page pointers.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Information Disclosure
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Red Os