{"id":"DEBIAN-CVE-2023-53481","details":"In the Linux kernel, the following vulnerability has been resolved:  ubi: ubi_wl_put_peb: Fix infinite loop when wear-leveling work failed  Following process will trigger an infinite loop in ubi_wl_put_peb():  \tubifs_bgt\t\tubi_bgt ubifs_leb_unmap   ubi_leb_unmap     ubi_eba_unmap_leb       ubi_wl_put_peb\twear_leveling_worker                           e1 = rb_entry(rb_first(&ubi-\u003eused) \t\t\t  e2 = get_peb_for_wl(ubi) \t\t\t  ubi_io_read_vid_hdr  // return err (flash fault) \t\t\t  out_error: \t\t\t    ubi-\u003emove_from = ubi-\u003emove_to = NULL \t\t\t    wl_entry_destroy(ubi, e1) \t\t\t      ubi-\u003elookuptbl[e-\u003epnum] = NULL       retry:         e = ubi-\u003elookuptbl[pnum];\t// return NULL \tif (e == ubi-\u003emove_from) {\t// NULL == NULL gets true \t  goto retry;\t\t\t// infinite loop !!!  $ top   PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     COMMAND   7676 root     20   0       0      0      0 R 100.0  0.0  ubifs_bgt0_0  Fix it by:  1) Letting ubi_wl_put_peb() returns directly if wearl leveling entry has     been removed from 'ubi-\u003elookuptbl'.  2) Using 'ubi-\u003ewl_lock' protecting wl entry deletion to preventing an     use-after-free problem for wl entry in ubi_wl_put_peb().  Fetch a reproducer in [Link].","modified":"2026-09-15T09:02:51.437005508Z","published":"2025-10-01T12:15:50.743Z","upstream":["CVE-2023-53481"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53481"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53481.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53481.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53481.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}