CVE-2023-53593
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53593 is a vulnerability in the Linux kernel related to a folio lock release issue in the CIFS filesystem. The vulnerability was disclosed on October 4, 2025. The issue affects the cifs_readpage_worker functionality when interacting with fscache (NVD).

Technical details

The vulnerability occurs when cifs_readpage_worker is called, where the call contract requires the callee to unlock the page. According to the documentation in Documentation/filesystems/vfs.rst, the filesystem should unlock the folio once the read has completed, regardless of success or failure. When fscache is in use and a cache hit occurs during a read, the page lock is leaked. While cifs_readpage_from_fscache marks the page clean in __cifs_readpage_from_fscache on success, it does not free the folio lock (NVD).

Impact

When the vulnerability is triggered, it results in a deadlock condition that requires a system reboot to resolve. The issue manifests when subsequent reads (via mmap) attempt to access the affected page, leading to a stuck process that cannot proceed (NVD).

Mitigation and workarounds

The vulnerability has been fixed in various Linux distributions. Debian has released fixes in multiple versions: bullseye (5.10.244-1), bookworm (6.1.153-1), trixie (6.12.48-1), and sid (6.16.12-2) (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-cross-headers
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-core
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management