Junglewise Threat Intelligence

CVE-2023-53421: Linux Kernel NULL pointer dereference in blk-cgroup

CVE-2023-53421 · Severity: medium · CVSS 5.5 · Published 2025-09-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's block storage management component could allow a local user to crash the system. The issue occurs when resetting certain storage statistics, leading to a kernel panic. This results in a complete loss of system availability, potentially disrupting operations and requiring a manual reboot.

Technical details

A NULL pointer dereference vulnerability exists in the Linux kernel's blk-cgroup (Block Control Group) subsystem. The issue resides in the blkcg_reset_stats() function, where the blkg_iostat_set structure is cleared via memset but fails to re-initialize the 'blkg' and 'sync' fields. This lack of re-initialization leads to a NULL pointer access of the blkg pointer during subsequent operations, resulting in a kernel panic. An attacker with local access and the ability to trigger a statistics reset (typically via cgroup v1 interfaces) can exploit this to cause a Denial of Service (DoS). The vulnerability has been addressed by ensuring these fields are properly re-initialized after memory clearing.

Affected products

  • Linux Linux Kernel 5.5 to 6.3.13, 6.4 to 6.4.4

Timeline

  • 2023-06-06: other: Initial patch submitted to LKML
  • 2025-09-18: disclosed: CVE published by kernel.org
  • 2025-09-18: advisory: NVD entry created

References

Related threats