cbcvebase.
CVE-2023-53672
published 2025-10-07

CVE-2023-53672: In the Linux kernel, the following vulnerability has been resolved: btrfs: output extra debug info if we failed to find an inline backref [BUG] Syzbot reported…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: output extra debug info if we failed to find an inline backref [BUG] Syzbot reported several warning triggered inside lookup_inline_extent_backref(). [CAUSE] As usual, the reproducer doesn't reliably trigger locally here, but at least we know the WARN_ON() is triggered when an inline backref can not be found, and it can only be triggered when @insert is true. (I.e. inserting a new inline backref, which means the backref should already exist) [ENHANCEMENT] After the WARN_ON(), dump all the parameters and the extent tree leaf to help debug.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 376b41524b71e494514720bd6114325b0a2ed19c376b41524b71e494514720bd6114325b0a2ed19c
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 400e08a16604b534fdd82c5a288fa150d04f5f79400e08a16604b534fdd82c5a288fa150d04f5f79
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 7afbfde45d665953b4d5a42a721e15bf0315d89b7afbfde45d665953b4d5a42a721e15bf0315d89b
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < b7c3cf2f6c42e6688b1c37215a0b1663f982f915b7c3cf2f6c42e6688b1c37215a0b1663f982f915
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 6994f806c6d1ae8b59344d3700358547f3b3fe1d6994f806c6d1ae8b59344d3700358547f3b3fe1d
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 28062cd6eda04035d8f6ded2001292ac8b49614928062cd6eda04035d8f6ded2001292ac8b496149
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < e70ba449b04b40584bdabb383d10455397cbf177e70ba449b04b40584bdabb383d10455397cbf177
linuxlinux>= 492104c866cb1b62a11393adccb477f5cd2c7768 < 7f72f50547b7af4ddf985b07fc56600a4deba2817f72f50547b7af4ddf985b07fc56600a4deba281
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 3.9.1 < 4.14.3264.14.326
linuxlinux_kernel>= 4.15 < 4.19.2954.19.295
linuxlinux_kernel>= 4.20 < 5.4.2575.4.257
linuxlinux_kernel>= 5.11 < 5.15.1335.15.133
linuxlinux_kernel>= 5.16 < 6.1.556.1.55
linuxlinux_kernel>= 5.5 < 5.10.1975.10.197
linuxlinux_kernel>= 6.2 < 6.5.56.5.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.