Answer in brief
CVE-2023-53083 records a Critical severity (CVSS 9.8) vulnerability in nfsd: don't replace page in rq_pages if it's a continuation of last page. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc3:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bf1cbe2f3650b4f4a8add6af933c6d7f6af1f361 <8235cd619db6e67f1d7d26c55f1f3e4e575c947d || >=56bc7e3821e847a6cc8027ddaba32e9a440225a5 <12eca509234acb6b666802edf77408bb70d7bfca || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <51ddb84baff6f09ad62b5999ece3ec172e4e3568 || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <0101067f376eb7b9afd00279270f25d5111a091d || >=91e23b1c39820bfed642119ff6b6ef9f43cf09ce <27c934dd8832dd40fd34776f916dc201e18b319b | 8235cd619db6e67f1d7d26c55f1f3e4e575c947d, 12eca509234acb6b666802edf77408bb70d7bfca, 51ddb84baff6f09ad62b5999ece3ec172e4e3568, 0101067f376eb7b9afd00279270f25d5111a091d, 27c934dd8832dd40fd34776f916dc201e18b319b |
| Linux/Linuxgeneric | 5.19 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page. nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array _again_ corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves. If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.
Quoted source text, attributed separately from HOL analysis.