cbcvebase.
CVE-2023-53618
published 2025-10-07

CVE-2023-53618: In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported a crash…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.4th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported a crash that an ASSERT() got triggered inside prepare_to_merge(). That ASSERT() makes sure the reloc tree is properly pointed back by its subvolume tree. [CAUSE] After more debugging output, it turns out we had an invalid reloc tree: BTRFS error (device loop1): reloc tree mismatch, root 8 has no reloc root, expect reloc root key (-8, 132, 8) gen 17 Note the above root key is (TREE_RELOC_OBJECTID, ROOT_ITEM, QUOTA_TREE_OBJECTID), meaning it's a reloc tree for quota tree. But reloc trees can only exist for subvolumes, as for non-subvolume trees, we just COW the involved tree block, no need to create a reloc tree since those tree blocks won't be shared with other trees. Only subvolumes tree can share tree blocks with other trees (thus they have BTRFS_ROOT_SHAREABLE flag). Thus this new debug output proves my previous assumption that corrupted on-disk data can trigger that ASSERT(). [FIX] Besides the dedicated fix and the graceful exit, also let tree-checker to check such root keys, to make sure reloc trees can only exist for subvolumes.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 259ee7754b6793af8bdd77f9ca818bc41cfe9541 < 314135b7bae9618a317874ae195272682cf2d5d4314135b7bae9618a317874ae195272682cf2d5d4
linuxlinux>= 259ee7754b6793af8bdd77f9ca818bc41cfe9541 < 3ae93b316ca4b8b3c33798ef1d210355f2fb93183ae93b316ca4b8b3c33798ef1d210355f2fb9318
linuxlinux>= 259ee7754b6793af8bdd77f9ca818bc41cfe9541 < 84256e00eeca73c529fc6196e478cc89b809815784256e00eeca73c529fc6196e478cc89b8098157
linuxlinux>= 259ee7754b6793af8bdd77f9ca818bc41cfe9541 < 6ebcd021c92b8e4b904552e4d87283032100796d6ebcd021c92b8e4b904552e4d87283032100796d
linuxlinux>= 5.2.19 < 5.35.3
linuxlinux>= 5.3.4 < 5.45.4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.16 < 6.1.466.1.46
linuxlinux_kernel>= 5.2.19 < 5.35.3
linuxlinux_kernel>= 5.3.4 < 5.15.1275.15.127
linuxlinux_kernel>= 6.2 < 6.4.116.4.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.