CVE-2023-53695 (GCVE-0-2023-53695)
Vulnerability from cvelistv5
Published
2025-10-22 13:23
Modified
2026-08-05 09:15
Summary
In the Linux kernel, the following vulnerability has been resolved: udf: Detect system inodes linked into directory hierarchy When UDF filesystem is corrupted, hidden system inodes can be linked into directory hierarchy which is an avenue for further serious corruption of the filesystem and kernel confusion as noticed by syzbot fuzzed images. Refuse to access system inodes linked into directory hierarchy and vice versa.
Impacted products
Vendor Product Version
Linux Linux Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 6174c2eb8ecef271159bdcde460ce8af54d8f72f
Version: 801c7a20d255e300ab51a6fcb1d0e218d136b16f
Version: 3.17.2   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/udf/inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "1dc71eeb198a8daa17d0c995998a53b0b749a158",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "d747b31e2925a2f384e7dd1901a2e5bc5f984ed8",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "a44ec34b90440ada190924f5908b97026504fdcd",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "37e74003d81e79457535cbbdfa1603431c03fac0",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "1f328751b65c49c13a312d67a3bf27766b85baf7",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "9e3b5ef7d02eaa6553e79b4af9bd99227280f245",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "lessThan": "85a37983ec69cc9fcd188bc37c4de15ee326355a",
              "status": "affected",
              "version": "6174c2eb8ecef271159bdcde460ce8af54d8f72f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "801c7a20d255e300ab51a6fcb1d0e218d136b16f",
              "versionType": "git"
            },
            {
              "lessThan": "3.18",
              "status": "affected",
              "version": "3.17.2",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/udf/inode.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.18"
            },
            {
              "lessThan": "3.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.278",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.235",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.173",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.99",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.16",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.2.*",
              "status": "unaffected",
              "version": "6.2.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.278",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.235",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.173",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.99",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.16",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.2.3",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "3.17.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Detect system inodes linked into directory hierarchy\n\nWhen UDF filesystem is corrupted, hidden system inodes can be linked\ninto directory hierarchy which is an avenue for further serious\ncorruption of the filesystem and kernel confusion as noticed by syzbot\nfuzzed images. Refuse to access system inodes linked into directory\nhierarchy and vice versa."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Exploitation requires a crafted UDF filesystem image to be mounted on the target and then accessed through ordinary local filesystem syscalls (lookup, open, unlink, write, truncate). There is no network-facing path into fs/udf.\nAC:L - The attacker fully controls the on-disk image and simply points a directory entry at the same block as a hidden system inode (VAT/metadata/mirror/bitmap FE), which deterministically returns the cached hidden inode from iget_locked() with the link-count-0 check bypassed. The follow-on races against the unlocked udf_try_read_meta()/inode_bmap() walk are also attacker-driven from two of the attacker\u0027s own threads.\nPR:L - udf is FS_REQUIRES_DEV without FS_USERNS_MOUNT, but the realistic delivery is a low-privileged local user\u0027s removable disc/USB/ISO auto-mounted by udisks2 on desktops, kiosks and shared workstations; every subsequent step (open, unlink, ftruncate, write on the exposed system inode) needs only ordinary unprivileged file access.\nUI:N - In the auto-mount scenario the attacker inserts the media and performs all filesystem operations themselves, so no separate victim action is required.\nS:U - The corruption and crash stay within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Exposing a system inode as a normal file lets the attacker mutate its extent list while udf_try_read_meta() walks it with no i_data_sem held, yielding out-of-bounds reads past the i_data kmalloc buffer and parsing of freed/reallocated blocks, so kernel heap contents can be surfaced through ordinary file reads.\nI:H - The same inode is simultaneously the kernel\u0027s internal block-translation table and a user-writable file, so writes and truncates rewrite in-use metadata mappings, and udf_free_inode()/udf_free_blocks() releases blocks the superblock is still using \u2014 unsynchronized modification of live kernel filesystem state that is exploitable for further memory corruption.\nA:H - syzbot reproduced a kernel WARNING in udf_free_inode() via udf_evict_inode() (udf_updated_lvid, which also carries a BUG_ON), which panics under panic_on_warn, and the resulting metadata-mapping corruption cascades into further oopses."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:15:35.101Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1dc71eeb198a8daa17d0c995998a53b0b749a158"
        },
        {
          "url": "https://git.kernel.org/stable/c/d747b31e2925a2f384e7dd1901a2e5bc5f984ed8"
        },
        {
          "url": "https://git.kernel.org/stable/c/a44ec34b90440ada190924f5908b97026504fdcd"
        },
        {
          "url": "https://git.kernel.org/stable/c/37e74003d81e79457535cbbdfa1603431c03fac0"
        },
        {
          "url": "https://git.kernel.org/stable/c/1f328751b65c49c13a312d67a3bf27766b85baf7"
        },
        {
          "url": "https://git.kernel.org/stable/c/9e3b5ef7d02eaa6553e79b4af9bd99227280f245"
        },
        {
          "url": "https://git.kernel.org/stable/c/85a37983ec69cc9fcd188bc37c4de15ee326355a"
        }
      ],
      "title": "udf: Detect system inodes linked into directory hierarchy",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-53695",
    "datePublished": "2025-10-22T13:23:36.524Z",
    "dateReserved": "2025-10-22T13:21:37.344Z",
    "dateUpdated": "2026-08-05T09:15:35.101Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…