cbcvebase.
CVE-2023-53473
published 2025-10-01

CVE-2023-53473: In the Linux kernel, the following vulnerability has been resolved: ext4: improve error handling from ext4_dirhash() The ext4_dirhash() will *almost* never…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: improve error handling from ext4_dirhash() The ext4_dirhash() will *almost* never fail, especially when the hash tree feature was first introduced. However, with the addition of support of encrypted, casefolded file names, that function can most certainly fail today. So make sure the callers of ext4_dirhash() properly check for failures, and reflect the errors back up to their callers.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= b886ee3e778ec2ad43e276fd378ab492cf6819b7 < b2531936118deb3f479c4fa1bcd787b74b8faa6ab2531936118deb3f479c4fa1bcd787b74b8faa6a
linuxlinux>= b886ee3e778ec2ad43e276fd378ab492cf6819b7 < f68876aeef96ef8b708ab10b9cb47ce0a5adb424f68876aeef96ef8b708ab10b9cb47ce0a5adb424
linuxlinux>= b886ee3e778ec2ad43e276fd378ab492cf6819b7 < 70d579aefa652a06af97e013e3fbbabbe5a4355370d579aefa652a06af97e013e3fbbabbe5a43553
linuxlinux>= b886ee3e778ec2ad43e276fd378ab492cf6819b7 < c1fae027da61fe8e7eb99f7244297e81bc0f1e43c1fae027da61fe8e7eb99f7244297e81bc0f1e43
linuxlinux>= b886ee3e778ec2ad43e276fd378ab492cf6819b7 < 4b3cb1d108bfc2aebb0d7c8a52261a53cf7f57864b3cb1d108bfc2aebb0d7c8a52261a53cf7f5786
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.16 < 6.1.296.1.29
linuxlinux_kernel>= 5.2 < 5.15.1125.15.112
linuxlinux_kernel>= 6.2 < 6.2.166.2.16
linuxlinux_kernel>= 6.3 < 6.3.36.3.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.