Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — NFSv4.2: Rework scratch handling for READ_PLUS (again)
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0040 33.4 —
AFFECTED
Product Versions Fixed
Linux 886959f425b6a936a30b82a297ae3aecb3b8230f – —
Linux 6.4 – 6.4.16
TIMELINE
Sep 17 Reserved by Linux
Sep 17 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2023-53360 (Linux). CVSS 9.8 → 5.5 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: Rework scratch handling for READ_PLUS (again)
I found that the read code might send multiple requests using the same
nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is
how we ended up occasionally double-freeing the scratch buffer, but also
means we set a NULL pointer but non-zero length to the xdr scratch
buffer. This results in an oops the first time decoding needs to copy
something to scratch, which frequently happens when decoding READ_PLUS
hole segments.
I fix this by moving scratch handling into the pageio read code. I
provide a function to allocate scratch space for decoding read replies,
and free the scratch buffer when the nfs_pgio_header is freed.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 17, 2025 | Reserved | Reserved by Linux |
| September 17, 2025 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2023-53360 (Linux). CVSS 9.8 → 5.5 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 886959f425b6a936a30b82a297ae3aecb3b8230f | — |
| Linux | Linux | — | 6.4 | 6.4.16 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-53360 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.