Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: don't hold ni_lock when calling truncate_setsize() syzbot is reporting hung task at do_user_addr_fault() [1], for there is a silent deadlock between PG_locked bit and ni_lock lock. Since filemap_update_page() calls filemap_read_folio() after calling folio_trylock() which will set PG_locked bit, ntfs_truncate() must not call truncate_setsize() which will wait for PG_locked bit to be cleared when holding ni_lock lock.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.15, < 5.15.87 |
References
- https://git.kernel.org/stable/c/0226635c304cfd5c9db9b78c259cb713819b057ePatch
- https://git.kernel.org/stable/c/6bb6b1c6b0c31e36736b87a39dd1cbbd9d5ec22fPatch
- https://git.kernel.org/stable/c/73fee7e1e5ea11b51c51c46e0577a197ca3602cfPatch
- https://git.kernel.org/stable/c/8414983c2e649364d8af29080a0869266b31abb6Patch
FAQ
What is CVE-2023-53163?
CVE-2023-53163 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: don't hold ni_lock when calling truncate_setsize() syzbot is reporting hung task at do_user_addr_fault() [1], for there ...
How severe is CVE-2023-53163?
CVE-2023-53163 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53163?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.