CVE-2023-53618Linux vulnerability

6 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateApr 20

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported a crash that an ASSERT() got triggered inside prepare_to_merge(). That ASSERT() makes sure the reloc tree is properly pointed back by its subvolume tree. [CAUSE] After more debugging output, it turns out we had an invalid reloc tree: BTRFS error (device loop1): reloc tree mismatch, root 8 has no reloc root, expect reloc root key (-8, 132, 8) ge

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.2.195.3+4
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linux259ee7754b6793af8bdd77f9ca818bc41cfe9541314135b7bae9618a317874ae195272682cf2d5d4+6
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

3
VulDB
Linux Kernel up to 5.15.126/6.1.45/6.4.10 btrfs assertion (WID-SEC-2025-2229)2026-04-20
OSV
CVE-2023-53618: In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported a2025-10-07
GHSA
GHSA-2244-8r8j-955v: In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: btrfs: reject invalid reloc tree root keys with stack dump2025-10-07
Debian
CVE-2023-53618: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: reje...2023