CVE-2023-53380
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's RAID10 implementation has been identified as CVE-2023-53380. The issue involves a null pointer dereference of 'mreplace' in raid10syncrequest function. The vulnerability was disclosed on September 18, 2025, affecting various Linux kernel versions (NVD).

Technical details

The vulnerability stems from inconsistent checks of 'mreplace' in raid10syncrequest(). There are two separate checks: the first check sets 'needreplace' and uses 'mreplace' later if no-Faulty 'mreplace' exists, while in the second check, 'mreplace' is set to NULL if it is Faulty, but 'needreplace' remains unchanged. This can lead to a null pointer dereference if Faulty is set between the two checks (Ubuntu).

Impact

The vulnerability affects multiple Linux distributions and their kernel variants, including Ubuntu's various kernel packages such as linux-hwe, linux-aws, linux-azure, and others. Several Ubuntu releases from 18.04 LTS to 24.04 LTS are affected, with some packages requiring updates (Ubuntu).

Mitigation and workarounds

The issue has been fixed by merging the two checks into one and replacing 'need_replace' with 'mreplace' since their values are always the same. Various Linux distributions have released patches for affected kernel versions. Ubuntu has provided fixes for multiple kernel packages across different releases (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management