CVE-2026-23053
Last modified
CVE-2026-23053 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a deadlock involving nfs_release_folio() Wang Zhaolong reports a deadlock involving NFSv4.1 state recovery waiting on kthreadd, which is attempting to reclaim memory by calling nfs_release_folio(). The latter cannot make progress due to state recovery being needed. It seems that the only safe thing to do here is to kick off a writeback of the folio, without waiting for completion, or else kicking off an asynchronous commit.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a deadlock involving nfs_release_folio() Wang Zhaolong reports a deadlock involving NFSv4.1 state recovery waiting on kthreadd, which is attempting to reclaim memory by calling nfs_release_folio(). The latter cannot make progress due to state recovery being needed. It seems that the only safe thing to do here is to kick off a writeback of the folio, without waiting for completion, or else kicking off an asynchronous commit.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 96780ca55e3cbf4f150fd5a833a61492c9947b5b, < a4810f8beb0122f032f10735f98d257aa6064f4c; >= 96780ca55e3cbf4f150fd5a833a61492c9947b5b, < 49d352bc263fe4a834233338bfaad31b3109addf; >= 96780ca55e3cbf4f150fd5a833a61492c9947b5b, < 19b4d9ab5e77843eac0429c019470c02f8710b55; >= 96780ca55e3cbf4f150fd5a833a61492c9947b5b, < cce0be6eb4971456b703aaeafd571650d314bcca |
| Linux | Linux | 6.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-23053?
How severe is CVE-2026-23053?
How do I fix CVE-2026-23053?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23048In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23049In the Linux kernel, the following vulnerability has been re…
- CVE-2026-2305The AddFunc Head & Footer Code plugin for WordPress is vulne…6.4
- CVE-2026-23050In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23051In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23052In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23054In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23055In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23056In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23057In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23058In the Linux kernel, the following vulnerability has been re…
- CVE-2026-23059In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-23053?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
