CVE-2023-53295
published 2025-09-16CVE-2023-53295: In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inline file…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
udf: Do not update file length for failed writes to inline files
When write to inline file fails (or happens only partly), we still
updated length of inline data as if the whole write succeeded. Fix the
update of length of inline data to happen only if the write succeeds.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5621f7a8139053d0c3c47fb68ee9f602139eb40a | 5621f7a8139053d0c3c47fb68ee9f602139eb40a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5a6c373d761f55635e175fa2f407544bae8f583b | 5a6c373d761f55635e175fa2f407544bae8f583b |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7bd8d9e1cf5607ee14407f4060b9a1dbb3c42802 | 7bd8d9e1cf5607ee14407f4060b9a1dbb3c42802 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < eb2133900cac2d2f78befd6be41666cf1a2315d9 | eb2133900cac2d2f78befd6be41666cf1a2315d9 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c5787d77a5c29fffd295d138bd118b334990a567 | c5787d77a5c29fffd295d138bd118b334990a567 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6837910aeb2c9101fc036dcd1b1f32615c20ec1a | 6837910aeb2c9101fc036dcd1b1f32615c20ec1a |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6d18cedc1ef0caeb1567cab660079e48844ff6d6 | 6d18cedc1ef0caeb1567cab660079e48844ff6d6 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 256fe4162f8b5a1625b8603ca5f7ff79725bfb47 | 256fe4162f8b5a1625b8603ca5f7ff79725bfb47 |
| linux | linux_kernel | < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 4.15 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.20 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.5 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2 < 6.2.3 | 6.2.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-482h-wv29-vp5r: In the Linux kernel, the following vulnerability has been resolved:
udf: Do not update file length for failed writes to inline files
When write to i
ghsa_unreviewed·2025-09-16
CVE-2023-53295 [MEDIUM] GHSA-482h-wv29-vp5r: In the Linux kernel, the following vulnerability has been resolved:
udf: Do not update file length for failed writes to inline files
When write to i
In the Linux kernel, the following vulnerability has been resolved:
udf: Do not update file length for failed writes to inline files
When write to inline file fails (or happens only partly), we still
updated length of inline data as if the whole write succeeded. Fix the
update of length of inline data to happen only if the write succeeds.
OSV
CVE-2023-53295: In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inl
osv·2025-09-16·CVSS 5.5
CVE-2023-53295 [MEDIUM] CVE-2023-53295: In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inl
In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inline file fails (or happens only partly), we still updated length of inline data as if the whole write succeeded. Fix the update of length of inline data to happen only if the write succeeds.
Red Hat
kernel: udf: Do not update file length for failed writes to inline files
vendor_redhat·2025-09-16·CVSS 5.5
CVE-2023-53295 [MEDIUM] CWE-392 kernel: udf: Do not update file length for failed writes to inline files
kernel: udf: Do not update file length for failed writes to inline files
In the Linux kernel, the following vulnerability has been resolved:
udf: Do not update file length for failed writes to inline files
When write to inline file fails (or happens only partly), we still
updated length of inline data as if the whole write succeeded. Fix the
update of length of inline data to happen only if the write succeeds.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Pac
Debian
CVE-2023-53295: linux - In the Linux kernel, the following vulnerability has been resolved: udf: Do not...
vendor_debian·2023·CVSS 5.5
CVE-2023-53295 [MEDIUM] CVE-2023-53295: linux - In the Linux kernel, the following vulnerability has been resolved: udf: Do not...
In the Linux kernel, the following vulnerability has been resolved: udf: Do not update file length for failed writes to inline files When write to inline file fails (or happens only partly), we still updated length of inline data as if the whole write succeeded. Fix the update of length of inline data to happen only if the write succeeds.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/256fe4162f8b5a1625b8603ca5f7ff79725bfb47https://git.kernel.org/stable/c/5621f7a8139053d0c3c47fb68ee9f602139eb40ahttps://git.kernel.org/stable/c/5a6c373d761f55635e175fa2f407544bae8f583bhttps://git.kernel.org/stable/c/6837910aeb2c9101fc036dcd1b1f32615c20ec1ahttps://git.kernel.org/stable/c/6d18cedc1ef0caeb1567cab660079e48844ff6d6https://git.kernel.org/stable/c/7bd8d9e1cf5607ee14407f4060b9a1dbb3c42802https://git.kernel.org/stable/c/c5787d77a5c29fffd295d138bd118b334990a567https://git.kernel.org/stable/c/eb2133900cac2d2f78befd6be41666cf1a2315d9
2025-09-16
Published