CVE-2023-53804

Source
https://cve.org/CVERecord?id=CVE-2023-53804
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53804.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53804
Downstream
Related
Published
2025-12-09T00:01:01.787Z
Modified
2026-03-20T12:33:21.012259Z
Summary
nilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode()
Details

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix use-after-free bug of nilfsroot in nilfsevict_inode()

During unmount process of nilfs2, nothing holds nilfsroot structure after nilfs2 detaches its writer in nilfsdetachlogwriter(). However, since nilfsevictinode() uses nilfsroot for some cleanup operations, it may cause use-after-free read if inodes are left in "garbagelist" and released by nilfsdisposelist() at the end of nilfsdetachlog_writer().

Fix this issue by modifying nilfsevictinode() to only clear inode without additional metadata changes that use nilfs_root if the file system is degraded to read-only or the writer is detached.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53804.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e912a5b66837ee89fb025e67b5efeaa11930c2ce
Fixed
f31e18131ee2ce80a4da5c808221d25b1ae9ad6d
Fixed
2a782ea8ebd712a458466e3103e2881b4f886cb5
Fixed
116d53f09ff52e6f98e3fe1f85d8898d6ba26c68
Fixed
6b4205ea97901f822004e6c8d59484ccfda03faa
Fixed
b8427b8522d9ede53015ba45a9978ba68d1162f5
Fixed
acc2a40e428f12780004e1e9fce4722d88f909fd
Fixed
fb8e8d58f116d069e5939e1f786ac84e7fa4533e
Fixed
9b5a04ac3ad9898c4745cba46ea26de74ba56a8e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53804.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.37
Fixed
4.14.316
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.284
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.244
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.181
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.113
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.30
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.3.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53804.json"