CVE-2023-53285
published 2025-09-16CVE-2023-53285: In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extended…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the extended attributes in the inode body would have been
checked when the inode is first opened, but if someone is writing to
the block device while the file system is mounted, it's possible for
the inode table to get corrupted. Add bounds checking to avoid
reading beyond the end of allocated memory if this happens.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 5a229d21b98d132673096710e8281ef522dab1d1 | 5a229d21b98d132673096710e8281ef522dab1d1 |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205 | 3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205 |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 486efbbc9445dca7890a1b86adbccb88b91284b0 | 486efbbc9445dca7890a1b86adbccb88b91284b0 |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 4597554b4f7b29e7fd78aa449bab648f8da4ee2c | 4597554b4f7b29e7fd78aa449bab648f8da4ee2c |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < f22b274429e88d3dc7e79d375b56ce4f2f59f0b4 | f22b274429e88d3dc7e79d375b56ce4f2f59f0b4 |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f | 1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < e780058bd75614b66882bc02620ddbd884171560 | e780058bd75614b66882bc02620ddbd884171560 |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 88a06a94942c5c0a896e9da1113a6bb29e36cbef | 88a06a94942c5c0a896e9da1113a6bb29e36cbef |
| linux | linux | >= 67cf5b09a46f72e048501b84996f2f77bc42e947 < 2220eaf90992c11d888fe771055d4de330385f01 | 2220eaf90992c11d888fe771055d4de330385f01 |
| linux | linux_kernel | < 4.14.315 | 4.14.315 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.15 < 4.19.283 | 4.19.283 |
| linux | linux_kernel | >= 4.20 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 5.11 < 5.15.112 | 5.15.112 |
| linux | linux_kernel | >= 5.16 < 6.1.29 | 6.1.29 |
| linux | linux_kernel | >= 5.5 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2 < 6.2.16 | 6.2.16 |
| linux | linux_kernel | >= 6.3 < 6.3.3 | 6.3.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ext4: add bounds checking in get_max_inline_xattr_value_size()
vendor_redhat·2025-09-16·CVSS 7.8
CVE-2023-53285 [HIGH] CWE-125 kernel: ext4: add bounds checking in get_max_inline_xattr_value_size()
kernel: ext4: add bounds checking in get_max_inline_xattr_value_size()
In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the extended attributes in the inode body would have been
checked when the inode is first opened, but if someone is writing to
the block device while the file system is mounted, it's possible for
the inode table to get corrupted. Add bounds checking to avoid
reading beyond the end of allocated memory if this happens.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red
Debian
CVE-2023-53285: linux - In the Linux kernel, the following vulnerability has been resolved: ext4: add b...
vendor_debian·2023·CVSS 7.8
CVE-2023-53285 [HIGH] CVE-2023-53285: linux - In the Linux kernel, the following vulnerability has been resolved: ext4: add b...
In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extended attributes in the inode body would have been checked when the inode is first opened, but if someone is writing to the block device while the file system is mounted, it's possible for the inode table to get corrupted. Add bounds checking to avoid reading beyond the end of allocated memory if this happens.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
OSV
CVE-2023-53285: In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extend
osv·2025-09-16·CVSS 7.8
CVE-2023-53285 [HIGH] CVE-2023-53285: In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extend
In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extended attributes in the inode body would have been checked when the inode is first opened, but if someone is writing to the block device while the file system is mounted, it's possible for the inode table to get corrupted. Add bounds checking to avoid reading beyond the end of allocated memory if this happens.
GHSA
GHSA-whjr-jhc6-c22f: In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the exte
ghsa_unreviewed·2025-09-16
CVE-2023-53285 [HIGH] GHSA-whjr-jhc6-c22f: In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the exte
In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the extended attributes in the inode body would have been
checked when the inode is first opened, but if someone is writing to
the block device while the file system is mounted, it's possible for
the inode table to get corrupted. Add bounds checking to avoid
reading beyond the end of allocated memory if this happens.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1d2caddbeeee56fbbc36b428c5b909c3ad88eb7fhttps://git.kernel.org/stable/c/2220eaf90992c11d888fe771055d4de330385f01https://git.kernel.org/stable/c/3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205https://git.kernel.org/stable/c/4597554b4f7b29e7fd78aa449bab648f8da4ee2chttps://git.kernel.org/stable/c/486efbbc9445dca7890a1b86adbccb88b91284b0https://git.kernel.org/stable/c/5a229d21b98d132673096710e8281ef522dab1d1https://git.kernel.org/stable/c/88a06a94942c5c0a896e9da1113a6bb29e36cbefhttps://git.kernel.org/stable/c/e780058bd75614b66882bc02620ddbd884171560https://git.kernel.org/stable/c/f22b274429e88d3dc7e79d375b56ce4f2f59f0b4
2025-09-16
Published