CVE-2023-53083
A critical flaw in the Linux kernel’s NFS server can corrupt internal data structures when handling partial page reads, potentially leading to memory corruption or a crash. The issue occurs when the kernel mistakenly re‑adds a partially read page to an array, causing an overflow. The vulnerability has been fixed in the kernel.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, especially versions 6.3 and earlier, on systems running the NFS server. Typical users are system administrators managing Linux servers with NFS services.
Real-world impact
An attacker could exploit the flaw to corrupt memory, which may result in a denial‑of‑service crash or, in some cases, arbitrary code execution, allowing them to take control of the affected system.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication or user interaction, and it can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2023-53083.
NVD description indicates the vulnerability has been resolved.
Timeline
- May 2, 2025 · May 2, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.