cbcvebase.
CVE-2023-53081
published 2025-05-02

CVE-2023-53081: In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption after failed write When buffered write fails to copy data into…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix data corruption after failed write When buffered write fails to copy data into underlying page cache page, ocfs2_write_end_nolock() just zeroes out and dirties the page. This can leave dirty page beyond EOF and if page writeback tries to write this page before write succeeds and expands i_size, page gets into inconsistent state where page dirty bit is clear but buffer dirty bits stay set resulting in page data never getting written and so data copied to the page is lost. Fix the problem by invalidating page beyond EOF after failed write.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.204 < 4.14.3124.14.312
linuxlinux>= 4.19.155 < 4.19.2804.19.280
linuxlinux>= 4.9.242 < 4.104.10
linuxlinux>= 5.4.75 < 5.4.2405.4.240
linuxlinux>= 5.9.5 < 5.105.10
linuxlinux>= 6dbf7bb555981fb5faf7b691e8f6169fc2b2e63b < 91d7a4bd5656552d6259e2d0f8859f9e8cc5ef6891d7a4bd5656552d6259e2d0f8859f9e8cc5ef68
linuxlinux>= 6dbf7bb555981fb5faf7b691e8f6169fc2b2e63b < a9e53869cb43c96d6d851c491fd4e26430ab6ba6a9e53869cb43c96d6d851c491fd4e26430ab6ba6
linuxlinux>= 6dbf7bb555981fb5faf7b691e8f6169fc2b2e63b < 47eb055ad3588fc96d34e9e1dd87b210ce62906b47eb055ad3588fc96d34e9e1dd87b210ce62906b
linuxlinux>= 6dbf7bb555981fb5faf7b691e8f6169fc2b2e63b < 205759c6c18f54659b0b5976b14a52d1b3eb9f57205759c6c18f54659b0b5976b14a52d1b3eb9f57
linuxlinux>= 6dbf7bb555981fb5faf7b691e8f6169fc2b2e63b < 90410bcf873cf05f54a32183afff0161f44f971590410bcf873cf05f54a32183afff0161f44f9715
linuxlinux>= 7ce2b16bad2cbfa3fa7bbc42c4448914f639ca47 < c26f3ff4c0be590c1250f945ac2e4fc5fcdc5f45c26f3ff4c0be590c1250f945ac2e4fc5fcdc5f45
linuxlinux>= 7ed80e77c908cbaa686529a49f8ae0060c5caee7 < 1629f6f522b2d058019710466a84b240683bbee31629f6f522b2d058019710466a84b240683bbee3
linuxlinux>= f8a6a2ed4b7d1c3c8631eeb6d00572bc853094a8 < 4c24eb49ab44351424ac8fe8567f91ea48a060894c24eb49ab44351424ac8fe8567f91ea48a06089
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 4.14.204 < 4.14.3124.14.312
linuxlinux_kernel>= 4.19.155 < 4.19.2804.19.280
linuxlinux_kernel>= 4.9.242 < 4.104.10

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.