CVE-2023-53116
A critical bug in the Linux kernel’s NVMe target subsystem could let an attacker crash the system or run arbitrary code. The flaw occurs when a request is freed too early, leading to a use‑after‑free. The issue has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, particularly versions 6.3 and earlier that contain the nvmet target code.
Real-world impact
An attacker could cause the system to crash (denial of service) or potentially execute malicious code with kernel privileges, compromising confidentiality, integrity, and availability.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, with no user interaction, and it can fully compromise confidentiality, integrity, and availability.
What to do about it
- 011. Update your Linux kernel to version 6.3 or later, which contains the fix for the nvmet use‑after‑free bug.
- 022. Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- May 2, 2025 · May 2, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/04c394208831d5e0d5…patch
- git.kernel.org/stable/c/6173a77b7e9d3e202b…patch
- git.kernel.org/stable/c/8ed9813871038b25a9…patch
- git.kernel.org/stable/c/a6317235da8aa7cb97…patch
- git.kernel.org/stable/c/bcd535f07c58342302…patch
- git.kernel.org/stable/c/e5d99b29012bbf0e86…patch
- git.kernel.org/stable/c/f1d5888a5efe345b63…patch
- git.kernel.org/stable/c/fafcb4b26393870c45…patch