{"id":"DEBIAN-CVE-2023-53826","details":"In the Linux kernel, the following vulnerability has been resolved:  ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()  Wear-leveling entry could be freed in error path, which may be accessed again in eraseblk_count_seq_show(), for example:  __erase_worker                eraseblk_count_seq_show                                 wl = ubi-\u003elookuptbl[*block_number] \t\t\t\tif (wl)   wl_entry_destroy     ubi-\u003elookuptbl[e-\u003epnum] = NULL     kmem_cache_free(ubi_wl_entry_slab, e) \t\t                   erase_count = wl-\u003eec  // UAF!  Wear-leveling entry updating/accessing in ubi-\u003elookuptbl should be protected by ubi-\u003ewl_lock, fix it by adding ubi-\u003ewl_lock to serialize wl entry accessing between wl_entry_destroy() and eraseblk_count_seq_show().  Fetch a reproducer in [Link].","modified":"2026-09-15T08:47:33.198807922Z","published":"2025-12-09T16:17:21.457Z","upstream":["CVE-2023-53826"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53826"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53826.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53826.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53826.json"}}],"schema_version":"1.9.0"}