Answer in brief
CVE-2023-53360 records a Critical severity (CVSS 9.8) vulnerability in NFSv4.2: Rework scratch handling for READ_PLUS (again). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=886959f425b6a936a30b82a297ae3aecb3b8230f <adac9f0ddd2b291c7ce41f549fdb27a13616cff5 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <a2f4cb206bd94b3f4a7bb05fcdce9525283b5681 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <ae5d5672f1db711e91db6f52df5cb16ecd8f5692 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <303a78052091c81e9003915c521fdca1c7e117af | adac9f0ddd2b291c7ce41f549fdb27a13616cff5, a2f4cb206bd94b3f4a7bb05fcdce9525283b5681, ae5d5672f1db711e91db6f52df5cb16ecd8f5692, 303a78052091c81e9003915c521fdca1c7e117af |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Sep 17, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53360 records a Critical severity (CVSS 9.8) vulnerability in NFSv4.2: Rework scratch handling for READ_PLUS (again). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=886959f425b6a936a30b82a297ae3aecb3b8230f <adac9f0ddd2b291c7ce41f549fdb27a13616cff5 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <a2f4cb206bd94b3f4a7bb05fcdce9525283b5681 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <ae5d5672f1db711e91db6f52df5cb16ecd8f5692 || >=fbd2a05f29a95d5b42b294bf47e55a711424965b <303a78052091c81e9003915c521fdca1c7e117af | adac9f0ddd2b291c7ce41f549fdb27a13616cff5, a2f4cb206bd94b3f4a7bb05fcdce9525283b5681, ae5d5672f1db711e91db6f52df5cb16ecd8f5692, 303a78052091c81e9003915c521fdca1c7e117af |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Sep 17, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.
Quoted source text, attributed separately from HOL analysis.