PT-2025-38210 · Linux+2 · Linux Kernel+2

Published

2023-06-09

·

Updated

2025-12-11

·

CVE-2023-53360

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to NFSv4.2 scratch handling for READ PLUS operations. The read code may send multiple requests using the same nfs pgio header, while nfs4 proc read setup() is only called once. This can lead to a double-free of the scratch buffer and setting a NULL pointer with a non-zero length to the xdr scratch buffer, resulting in an oops during decoding when handling READ PLUS hole segments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03353
CVE-2023-53360
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Affected Products

Astra Linux
Linux Kernel
Suse