CVE-2023-53526 (GCVE-0-2023-53526)
Vulnerability from cvelistv5
Published
2025-10-01 11:46
Modified
2026-08-05 09:14
Summary
In the Linux kernel, the following vulnerability has been resolved: jbd2: check 'jh->b_transaction' before removing it from checkpoint Following process will corrupt ext4 image: Step 1: jbd2_journal_commit_transaction __jbd2_journal_insert_checkpoint(jh, commit_transaction) // Put jh into trans1->t_checkpoint_list journal->j_checkpoint_transactions = commit_transaction // Put trans1 into journal->j_checkpoint_transactions Step 2: do_get_write_access test_clear_buffer_dirty(bh) // clear buffer dirty,set jbd dirty __jbd2_journal_file_buffer(jh, transaction) // jh belongs to trans2 Step 3: drop_cache journal_shrink_one_cp_list jbd2_journal_try_remove_checkpoint if (!trylock_buffer(bh)) // lock bh, true if (buffer_dirty(bh)) // buffer is not dirty __jbd2_journal_remove_checkpoint(jh) // remove jh from trans1->t_checkpoint_list Step 4: jbd2_log_do_checkpoint trans1 = journal->j_checkpoint_transactions // jh is not in trans1->t_checkpoint_list jbd2_cleanup_journal_tail(journal) // trans1 is done Step 5: Power cut, trans2 is not committed, jh is lost in next mounting. Fix it by checking 'jh->b_transaction' before remove it from checkpoint.
Impacted products
Vendor Product Version
Linux Linux Version: b832174b7f89df3ebab02f5b485d00127a0e1a6e
Version: e5c768d809a85e9efd0274b2efe69d4970cc0014
Version: 46f881b5b1758dc4a35fba4a643c10717d0cf427
Version: 46f881b5b1758dc4a35fba4a643c10717d0cf427
Version: 019b59aeb2af6b47d5c8e69c5dc1d731c8df0354
Version: 5.15.129   
Version: 6.1.50   
Version: 6.4.13   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/jbd2/checkpoint.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ef5fea70e5915afd64182d155e72bfb4f275e1fc",
              "status": "affected",
              "version": "b832174b7f89df3ebab02f5b485d00127a0e1a6e",
              "versionType": "git"
            },
            {
              "lessThan": "dbafe636db415299e54d9dfefc1003bda9e71c9d",
              "status": "affected",
              "version": "e5c768d809a85e9efd0274b2efe69d4970cc0014",
              "versionType": "git"
            },
            {
              "lessThan": "2298f2589903a8bc03061b54b31fd97985ab6529",
              "status": "affected",
              "version": "46f881b5b1758dc4a35fba4a643c10717d0cf427",
              "versionType": "git"
            },
            {
              "lessThan": "590a809ff743e7bd890ba5fb36bc38e20a36de53",
              "status": "affected",
              "version": "46f881b5b1758dc4a35fba4a643c10717d0cf427",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "019b59aeb2af6b47d5c8e69c5dc1d731c8df0354",
              "versionType": "git"
            },
            {
              "lessThan": "5.15.132",
              "status": "affected",
              "version": "5.15.129",
              "versionType": "semver"
            },
            {
              "lessThan": "6.1.54",
              "status": "affected",
              "version": "6.1.50",
              "versionType": "semver"
            },
            {
              "lessThan": "6.5",
              "status": "affected",
              "version": "6.4.13",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/jbd2/checkpoint.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "lessThan": "6.5",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.132",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.5.*",
              "status": "unaffected",
              "version": "6.5.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.6",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.132",
                  "versionStartIncluding": "5.15.129",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.54",
                  "versionStartIncluding": "6.1.50",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.5.4",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.4.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check \u0027jh-\u003eb_transaction\u0027 before removing it from checkpoint\n\nFollowing process will corrupt ext4 image:\nStep 1:\njbd2_journal_commit_transaction\n __jbd2_journal_insert_checkpoint(jh, commit_transaction)\n // Put jh into trans1-\u003et_checkpoint_list\n journal-\u003ej_checkpoint_transactions = commit_transaction\n // Put trans1 into journal-\u003ej_checkpoint_transactions\n\nStep 2:\ndo_get_write_access\n test_clear_buffer_dirty(bh) // clear buffer dirty\uff0cset jbd dirty\n __jbd2_journal_file_buffer(jh, transaction) // jh belongs to trans2\n\nStep 3:\ndrop_cache\n journal_shrink_one_cp_list\n  jbd2_journal_try_remove_checkpoint\n   if (!trylock_buffer(bh))  // lock bh, true\n   if (buffer_dirty(bh))     // buffer is not dirty\n   __jbd2_journal_remove_checkpoint(jh)\n   // remove jh from trans1-\u003et_checkpoint_list\n\nStep 4:\njbd2_log_do_checkpoint\n trans1 = journal-\u003ej_checkpoint_transactions\n // jh is not in trans1-\u003et_checkpoint_list\n jbd2_cleanup_journal_tail(journal)  // trans1 is done\n\nStep 5: Power cut, trans2 is not committed, jh is lost in next mounting.\n\nFix it by checking \u0027jh-\u003eb_transaction\u0027 before remove it from checkpoint."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable checkpoint scan is reached through ordinary VFS write/fsync syscalls and memory reclaim on a locally mounted ext4/ocfs2 filesystem. There is no network protocol handler involved, so the attacker needs local access (or an account on a shared host).\nAC:L - The attacker drives both sides of the race entirely from userspace \u2014 repeatedly re-dirtying already-checkpointed metadata blocks (rename/unlink/create storms against the same inode-table and bitmap blocks) while allocating memory to fire the jbd2 shrinker, on top of the commit-time `__jbd2_journal_clean_checkpoint_list()` path that runs every 5 seconds regardless. The window can be retried indefinitely at no cost, and the unclean shutdown that exposes the loss is routine in the deployment classes most affected (embedded, automotive, IoT, battery devices, cloud instances subject to host failure).\nPR:L - Any unprivileged local user with write access to any ext4/ocfs2 filesystem \u2014 /tmp or their own home directory suffices \u2014 generates the journal commits and reclaim pressure that hit the racy path. No capabilities, mount privileges, or user-namespace tricks are needed.\nUI:N - The attacker\u0027s own filesystem workload plus background commit/reclaim activity is sufficient; no action by any other user is required. The subsequent power loss or crash is an environmental event, not user interaction.\nS:U - The corruption stays within the kernel\u0027s own filesystem stack and the affected block device; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Rolling a metadata block back to a pre-trans1 state resurrects stale inode block pointers and allocation bitmaps, cross-linking blocks that were freed and have since been reallocated to other users\u0027 files, so an unprivileged user can end up reading arbitrary other-tenant file contents. The exposure is unbounded in size rather than a small fixed leak.\nI:H - The bug causes silent, permanent loss of committed filesystem metadata \u2014 inode tables, block/inode bitmaps, extent trees and directory blocks (and file data under data=journal) \u2014 that survives journal replay, which is exactly the \"corrupt ext4 image\" outcome described by the fix author. This is arbitrary, attacker-influenced modification of on-disk state with no integrity protection remaining.\nA:H - The resulting inconsistency triggers `ext4_error()` on the next access, which takes the filesystem read-only under the default errors=remount-ro or panics the machine under errors=panic; a corrupted root filesystem leaves an embedded, automotive, or appliance device unbootable until an offline fsck."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:14:37.200Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ef5fea70e5915afd64182d155e72bfb4f275e1fc"
        },
        {
          "url": "https://git.kernel.org/stable/c/dbafe636db415299e54d9dfefc1003bda9e71c9d"
        },
        {
          "url": "https://git.kernel.org/stable/c/2298f2589903a8bc03061b54b31fd97985ab6529"
        },
        {
          "url": "https://git.kernel.org/stable/c/590a809ff743e7bd890ba5fb36bc38e20a36de53"
        }
      ],
      "title": "jbd2: check \u0027jh-\u003eb_transaction\u0027 before removing it from checkpoint",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-53526",
    "datePublished": "2025-10-01T11:46:11.862Z",
    "dateReserved": "2025-10-01T11:39:39.407Z",
    "dateUpdated": "2026-08-05T09:14:37.200Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…