CVE-2023-53360
A critical bug in the Linux kernel’s NFSv4.2 read code can cause a double‑free that crashes the kernel. The issue arises when multiple read requests share a scratch buffer, leading to an oops during decoding. A patch has been released to correct the scratch handling.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel versions that include NFSv4.2 before the patch; any system running NFSv4.2 on Linux.
Real-world impact
An attacker could crash the system, causing a denial of service or potentially gain control if the crash can be leveraged further.
Why this severity
The CVSS score of 9.8 reflects that the flaw allows an attacker to crash the kernel with no authentication or user interaction, compromising confidentiality, integrity, and availability.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the NFSv4.2 patch that fixes the double‑free bug.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Sep 17, 2025 · Sep 17, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.