cbcvebase.
CVE-2023-53506
published 2025-10-01

CVE-2023-53506: In the Linux kernel, the following vulnerability has been resolved: udf: Do not bother merging very long extents When merging very long extents we try to push…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved: udf: Do not bother merging very long extents When merging very long extents we try to push as much length as possible to the first extent. However this is unnecessarily complicated and not really worth the trouble. Furthermore there was a bug in the logic resulting in corrupting extents in the file as syzbot reproducer shows. So just don't bother with the merging of extents that are too long together.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d52252a1de4cf96a34f722b0cd8902d8ff78eb57d52252a1de4cf96a34f722b0cd8902d8ff78eb57
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5d029799d381a9ee06209a222cae75f04c5d53045d029799d381a9ee06209a222cae75f04c5d5304
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3d20e3b768aff32112bdce8d3219d923ae75f9f13d20e3b768aff32112bdce8d3219d923ae75f9f1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 965982feb333aefa9256c0fe188b5f1b958aef63965982feb333aefa9256c0fe188b5f1b958aef63
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9a8d602f0723586e668bae7e65c832ceb9bcc8bc9a8d602f0723586e668bae7e65c832ceb9bcc8bc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < adac9ac6d2e04ea0782b91a00ba10706002f3ec4adac9ac6d2e04ea0782b91a00ba10706002f3ec4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7a965da79f2d22601f329cbfce588386b08475447a965da79f2d22601f329cbfce588386b0847544
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 53cafe1d6d8ef9f93318e5bfccc0d24f27d41ced53cafe1d6d8ef9f93318e5bfccc0d24f27d41ced
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 2.6.12.1 < 4.14.3084.14.308
linuxlinux_kernel>= 4.15 < 4.19.2764.19.276
linuxlinux_kernel>= 4.20 < 5.4.2355.4.235
linuxlinux_kernel>= 5.11 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 5.5 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.