CVE-2023-53420Out-of-bounds Read in Linux

CWE-125Out-of-bounds Read5 documents5 sources
Severity
7.1HIGHNVD
EPSS
0.0%
top 94.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BUG report from syzbot: BUG: KASAN: slab-out-of-bounds in ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] BUG: KASAN: slab-out-of-bounds in ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 Read of size 1 at addr ffff888021acaf3d by task syz-executor128/3632 Call Trace: ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDlinux/linux_kernel5.155.15.121+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linuxbe71b5cba2e6485e8959da7a9f9a44461a1bb074f3380d895e28a32632eb3609f5bd515adee4e5a1+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mpvx-hgx6-jw78: In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BU2025-09-18
OSV
CVE-2023-53420: In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BUG2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr()2025-09-18
Debian
CVE-2023-53420: linux - In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix p...2023
CVE-2023-53420 — Out-of-bounds Read in Linux | cvebase