CVE-2023-53083

Source
https://cve.org/CVERecord?id=CVE-2023-53083
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53083.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53083
Downstream
Published
2025-05-02T15:55:31Z
Modified
2026-08-12T03:51:44Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
nfsd: don't replace page in rq_pages if it's a continuation of last page
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: don't replace page in rq_pages if it's a continuation of last page

The splice read calls nfsd_splice_actor to put the pages containing file data into the svc_rqst->rq_pages array. It's possible however to get a splice result that only has a partial page at the end, if (e.g.) the filesystem hands back a short read that doesn't cover the whole page.

nfsd_splice_actor will plop the partial page into its rq_pages array and return. Then later, when nfsd_splice_actor is called again, the remainder of the page may end up being filled out. At this point, nfsd_splice_actor will put the page into the array again corrupting the reply. If this is done enough times, rq_next_page will overrun the array and corrupt the trailing fields -- the rq_respages and rq_next_page pointers themselves.

If we've already added the page to the array in the last pass, don't add it to the array a second time when dealing with a splice continuation. This was originally handled properly in nfsd_splice_actor, but commit 91e23b1c3982 ("NFSD: Clean up nfsd_splice_actor()") removed the check for it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53083.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf1cbe2f3650b4f4a8add6af933c6d7f6af1f361
Fixed
8235cd619db6e67f1d7d26c55f1f3e4e575c947d
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
56bc7e3821e847a6cc8027ddaba32e9a440225a5
Fixed
12eca509234acb6b666802edf77408bb70d7bfca
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
91e23b1c39820bfed642119ff6b6ef9f43cf09ce
Fixed
51ddb84baff6f09ad62b5999ece3ec172e4e3568
Fixed
0101067f376eb7b9afd00279270f25d5111a091d
Fixed
27c934dd8832dd40fd34776f916dc201e18b319b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53083.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.22
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53083.json"