cbcvebase.
CVE-2023-53100
published 2025-05-02

CVE-2023-53100: In the Linux kernel, the following vulnerability has been resolved: ext4: fix WARNING in ext4_update_inline_data Syzbot found the following issue: EXT4-fs…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix WARNING in ext4_update_inline_data Syzbot found the following issue: EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 without journal. Quota mode: none. fscrypt: AES-256-CTS-CBC using implementation "cts-cbc-aes-aesni" fscrypt: AES-256-XTS using implementation "xts-aes-aesni" ------------[ cut here ]------------ WARNING: CPU: 0 PID: 5071 at mm/page_alloc.c:5525 __alloc_pages+0x30a/0x560 mm/page_alloc.c:5525 Modules linked in: CPU: 1 PID: 5071 Comm: syz-executor263 Not tainted 6.2.0-rc1-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022 RIP: 0010:__alloc_pages+0x30a/0x560 mm/page_alloc.c:5525 RSP: 0018:ffffc90003c2f1c0 EFLAGS: 00010246 RAX: ffffc90003c2f220 RBX: 0000000000000014 RCX: 0000000000000000 RDX: 0000000000000028 RSI: 0000000000000000 RDI: ffffc90003c2f248 RBP: ffffc90003c2f2d8 R08: dffffc0000000000 R09: ffffc90003c2f220 R10: fffff52000785e49 R11: 1ffff92000785e44 R12: 0000000000040d40 R13: 1ffff92000785e40 R14: dffffc0000000000 R15: 1ffff92000785e3c FS: 0000555556c0d300(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f95d5e04138 CR3: 00000000793aa000 CR4: 00000000003506f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: __alloc_pages_node include/linux/gfp.h:237 [inline] alloc_pages_node include/linux/gfp.h:260 [inline] __kmalloc_large_node+0x95/0x1e0 mm/slab_common.c:1113 __do_kmalloc_node mm/slab_common.c:956 [inline] __kmalloc+0xfe/0x190 mm/slab_common.c:981 kmalloc include/linux/slab.h:584 [inline] kzalloc include/linux/slab.h:720 [inline] ext4_update_inline_data+0x236/0x6b0 fs/ext4/inline.c:346 ext4_update_inline_dir fs/ext4/inline.c:1115 [inline] ext4_try_add_inline_entry+0x328/0x990 fs/ext4/inline.c:1307 ext4_add_entry+0x5a4/0xeb0 fs/ext4

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < c5aa102b433b1890e1ccaa40c06826c77dda1665c5aa102b433b1890e1ccaa40c06826c77dda1665
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 39c5df2ca544368b44b59d0f6d80131e9076337139c5df2ca544368b44b59d0f6d80131e90763371
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 74d775083e9f3d9dadf9e3b5f3e0028d1ad0bd5c74d775083e9f3d9dadf9e3b5f3e0028d1ad0bd5c
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < a9bd94f67b27739bbe8583c52256502bd4cc7e83a9bd94f67b27739bbe8583c52256502bd4cc7e83
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < ca500cf2eceb5a8e93bf71ab97b5f7a18ecabce2ca500cf2eceb5a8e93bf71ab97b5f7a18ecabce2
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 35161cec76772f74526f5886ad4082ec48511d5c35161cec76772f74526f5886ad4082ec48511d5c
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 92eee6a82a9a6f9f83559e17a2b6b935e1a5cd2592eee6a82a9a6f9f83559e17a2b6b935e1a5cd25
linuxlinux>= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 2b96b4a5d9443ca4cad58b0040be455803c05a422b96b4a5d9443ca4cad58b0040be455803c05a42
linuxlinux_kernel< 4.14.3104.14.310
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 4.15 < 4.19.2784.19.278
linuxlinux_kernel>= 4.20 < 5.4.2375.4.237
linuxlinux_kernel>= 5.11 < 5.15.1035.15.103
linuxlinux_kernel>= 5.16 < 6.1.206.1.20
linuxlinux_kernel>= 5.5 < 5.10.1755.10.175
linuxlinux_kernel>= 6.2 < 6.2.76.2.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.