Answer in brief
CVE-2023-53111 records a High severity (CVSS 7.8) vulnerability in loop: Fix use-after-free issues. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <407badf73ec9fb0d5744bf2ca1745c1818aa222f || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <e3fda704903f6d1fc351412f1bc6620333959ada || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <6917395c4667cfb607ed8bf1826205a59414657c || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <9b0cb770f5d7b1ff40bea7ca385438ee94570eec | 407badf73ec9fb0d5744bf2ca1745c1818aa222f, e3fda704903f6d1fc351412f1bc6620333959ada, 6917395c4667cfb607ed8bf1826205a59414657c, 9b0cb770f5d7b1ff40bea7ca385438ee94570eec |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: loop: Fix use-after-free issues do_req_filebacked() calls blk_mq_complete_request() synchronously or asynchronously when using asynchronous I/O unless memory allocation fails. Hence, modify loop_handle_cmd() such that it does not dereference 'cmd' nor 'rq' after do_req_filebacked() finished unless we are sure that the request has not yet been completed. This patch fixes the following kernel crash: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000054 Call trace: css_put.42938+0x1c/0x1ac loop_process_work+0xc8c/0xfd4 loop_rootcg_workfn+0x24/0x34 process_one_work+0x244/0x558 worker_thread+0x400/0x8fc kthread+0x16c/0x1e0 ret_from_fork+0x10/0x20
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53111 records a High severity (CVSS 7.8) vulnerability in loop: Fix use-after-free issues. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <407badf73ec9fb0d5744bf2ca1745c1818aa222f || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <e3fda704903f6d1fc351412f1bc6620333959ada || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <6917395c4667cfb607ed8bf1826205a59414657c || >=bc07c10a3603a5ab3ef01ba42b3d41f9ac63d1b6 <9b0cb770f5d7b1ff40bea7ca385438ee94570eec | 407badf73ec9fb0d5744bf2ca1745c1818aa222f, e3fda704903f6d1fc351412f1bc6620333959ada, 6917395c4667cfb607ed8bf1826205a59414657c, 9b0cb770f5d7b1ff40bea7ca385438ee94570eec |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: loop: Fix use-after-free issues do_req_filebacked() calls blk_mq_complete_request() synchronously or asynchronously when using asynchronous I/O unless memory allocation fails. Hence, modify loop_handle_cmd() such that it does not dereference 'cmd' nor 'rq' after do_req_filebacked() finished unless we are sure that the request has not yet been completed. This patch fixes the following kernel crash: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000054 Call trace: css_put.42938+0x1c/0x1ac loop_process_work+0xc8c/0xfd4 loop_rootcg_workfn+0x24/0x34 process_one_work+0x244/0x558 worker_thread+0x400/0x8fc kthread+0x16c/0x1e0 ret_from_fork+0x10/0x20
Quoted source text, attributed separately from HOL analysis.