CVE-2023-53194Use After Free in Linux

CWE-416Use After Free5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 95.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This adds a length check to guarantee the retrieved index root is legit. [ 162.459513] BUG: KASAN: use-after-free in hdr_find_e.isra.0+0x10c/0x320 [ 162.460176] Read of size 2 at addr ffff8880037bca99 by task mount/243 [ 162.460851] [ 162.461252] CPU: 0 PID: 243 Comm: mount Not tainted 6.0.0-rc7 #42 [ 162.461744] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.155.15.113+2
Debianlinux/linux_kernel< 6.1.82-1+2
CVEListV5linux/linux4534a70b7056fd4b9a1c6db5a4ce3c98546b291e85afd3007465f8bc74afffbf5b84ec29f5310b03+4
debiandebian/linux< linux 6.1.82-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c2fc-xc59-v4h9: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This adds a length check to guarante2025-09-15
OSV
CVE-2023-53194: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add length check in indx_get_root This adds a length check to guarantee2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: fs/ntfs3: Add length check in indx_get_root2025-09-15
Debian
CVE-2023-53194: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: A...2023
CVE-2023-53194 — Use After Free in Linux | cvebase