{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2023-53608",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2023-53608"
  ],
  "published": "2025-10-04T15:52:53Z",
  "summary": "nilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential UAF of struct nilfs_sc_info in nilfs_segctor_thread()\n\nThe finalization of nilfs_segctor_thread() can race with\nnilfs_segctor_kill_thread() which terminates that thread, potentially\ncausing a use-after-free BUG as KASAN detected.\n\nAt the end of nilfs_segctor_thread(), it assigns NULL to \"sc_task\" member\nof \"struct nilfs_sc_info\" to indicate the thread has finished, and then\nnotifies nilfs_segctor_kill_thread() of this using waitqueue\n\"sc_wait_task\" on the struct nilfs_sc_info.\n\nHowever, here, immediately after the NULL assignment to \"sc_task\", it is\npossible that nilfs_segctor_kill_thread() will detect it and return to\ncontinue the deallocation, freeing the nilfs_sc_info structure before the\nthread does the notification.\n\nThis fixes the issue by protecting the NULL assignment to \"sc_task\" and\nits notification, with spinlock \"sc_state_lock\" of the struct\nnilfs_sc_info.  Since nilfs_segctor_kill_thread() does a final check to\nsee if \"sc_task\" is NULL with \"sc_state_lock\" locked, this can eliminate\nthe race.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.1.21-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v6",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7l",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v8",
            "binary_version": "1:6.1.21-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.1.21-1+rpt1": {
            "linux_commit": "0afb5e98488aed7017b9bf321b575d0177feb7ed",
            "upstream_version": "6.1.21",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.24"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-53608"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/034cce77d52ba013ce62b4f5258c29907eb1ada5"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/0dbf0e64b91ee8fcb278aea93eb06fc7d56ecbcc"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/613bf23c070d11c525268f2945aa594704a9b764"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/f32297dba338dc06d62286dedb3cdbd5175b1719"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/92684e02654c91a61a0b0561433b710bcece19fe"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/bae009a2f1b7c2011d2e92d8c84868d315c0b97e"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/b4d80bd6370b81a1725b6b8f7894802c23a14e9f"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/6be49d100c22ffea3287a4b19d7639d259888e33"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-08-05T11:24:39Z"
  }
}
