Wind River Support Network

HomeDefectsLIN1023-15330
Fixed

LIN1023-15330 : Security Advisory - linux - CVE-2023-53380

Created: Sep 19, 2025    Updated: Sep 22, 2025
Resolved Date: Sep 22, 2025
Found In Version: 10.23.30.1
Fix Version: 10.23.30.2
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  md/raid10: fix null-ptr-deref of mreplace in raid10_sync_request  There are two check of 'mreplace' in raid10_sync_request(). In the first check, 'need_replace' will be set and 'mreplace' will be used later if no-Faulty 'mreplace' exists, In the second check, 'mreplace' will be set to NULL if it is Faulty, but 'need_replace' will not be changed accordingly. null-ptr-deref occurs if Faulty is set between two check.  Fix it by merging two checks into one. And replace 'need_replace' with 'mreplace' because their values are always the same.

CVEs


Live chat
Online