DEBIAN-CVE-2023-53301

Source
https://security-tracker.debian.org/tracker/CVE-2023-53301
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53301.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2023-53301
Upstream
Published
2025-09-16T08:15:39.517Z
Modified
2026-01-28T10:18:32.334968Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix kernel crash due to null io->bio We should return when io->bio is null before doing anything. Otherwise, panic. BUG: kernel NULL pointer dereference, address: 0000000000000010 RIP: 0010:_submitmergedwritecond+0x164/0x240 [f2fs] Call Trace: <TASK> f2fssubmitmergedwrite+0x1d/0x30 [f2fs] commitcheckpoint+0x110/0x1e0 [f2fs] f2fswritecheckpoint+0x9f7/0xf00 [f2fs] ? _pfxissuecheckpointthread+0x10/0x10 [f2fs] _checkpointandcompletereqs+0x84/0x190 [f2fs] ? preemptcountadd+0x82/0xc0 ? _pfxissuecheckpointthread+0x10/0x10 [f2fs] issuecheckpointthread+0x4c/0xf0 [f2fs] ? _pfxautoremovewakefunction+0x10/0x10 kthread+0xff/0x130 ? _pfxkthread+0x10/0x10 retfromfork+0x2c/0x50 </TASK>

References

Affected packages

Debian:12 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.20-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53301.json"

Debian:13 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.20-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53301.json"

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.20-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53301.json"