CVE-2023-53683
published 2025-10-07CVE-2023-53683: In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for
crafted filesystem image can contain bogus length. There conditions are
not kernel bugs that can justify kernel to panic.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1f881d9201f6e0a917004a14329f9ff3d0bfa1e5 < c8daee66585897a4c90d937c91e762100237bff9 | c8daee66585897a4c90d937c91e762100237bff9 |
| linux | linux | >= 4.14.303 < 4.14.316 | 4.14.316 |
| linux | linux | >= 4.19.270 < 4.19.284 | 4.19.284 |
| linux | linux | >= 48d9e2e6de01ed35e965eb549758a837c07b601d < 37cab61a52d6f42b2d961c51bcf369f09e235fb5 | 37cab61a52d6f42b2d961c51bcf369f09e235fb5 |
| linux | linux | >= 5.10.163 < 5.10.181 | 5.10.181 |
| linux | linux | >= 5.15.87 < 5.15.113 | 5.15.113 |
| linux | linux | >= 5.4.229 < 5.4.244 | 5.4.244 |
| linux | linux | >= 55d1cbbbb29e6656c662ee8f73ba1fc4777532eb < 48960a503fcec76d3f72347b7e679dda08ca43be | 48960a503fcec76d3f72347b7e679dda08ca43be |
| linux | linux | >= 55d1cbbbb29e6656c662ee8f73ba1fc4777532eb < 3a9d68d84b2e41ba3f2a727b36f035fad6800492 | 3a9d68d84b2e41ba3f2a727b36f035fad6800492 |
| linux | linux | >= 55d1cbbbb29e6656c662ee8f73ba1fc4777532eb < 81b21c0f0138ff5a499eafc3eb0578ad2a99622c | 81b21c0f0138ff5a499eafc3eb0578ad2a99622c |
| linux | linux | >= 781fa141414ef18b52f15037497155f80bf0ecab < a75d9211a07fed513c08c5d4861c4a36ac6a74fe | a75d9211a07fed513c08c5d4861c4a36ac6a74fe |
| linux | linux | >= ab778439c6fa0071698b62a351f79d319fd72c53 < c074913b12db3632b11588b31bbfb0fa80a0a1c9 | c074913b12db3632b11588b31bbfb0fa80a0a1c9 |
| linux | linux | >= f62f5ee63052324ad94dd05091743d9e09f72070 < 61af77acd039ffd221bf7adf0dc95d0a4d377505 | 61af77acd039ffd221bf7adf0dc95d0a4d377505 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.14.303 < 4.14.316 | 4.14.316 |
| linux | linux_kernel | >= 4.19.270 < 4.19.284 | 4.19.284 |
| linux | linux_kernel | >= 5.10.163 < 5.10.181 | 5.10.181 |
| linux | linux_kernel | >= 5.15.87 < 5.15.113 | 5.15.113 |
| linux | linux_kernel | >= 5.16 < 6.1.30 | 6.1.30 |
| linux | linux_kernel | >= 5.4.229 < 5.4.244 | 5.4.244 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53683: In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitt
osv·2025-10-07·CVSS 5.5
CVE-2023-53683 [MEDIUM] CVE-2023-53683: In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitt
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are not kernel bugs that can justify kernel to panic.
GHSA
GHSA-j4vp-rrf4-3xj8: In the Linux kernel, the following vulnerability has been resolved:
fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
syzbot is hi
ghsa_unreviewed·2025-10-07
CVE-2023-53683 [MEDIUM] CWE-617 GHSA-j4vp-rrf4-3xj8: In the Linux kernel, the following vulnerability has been resolved:
fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
syzbot is hi
In the Linux kernel, the following vulnerability has been resolved:
fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for
crafted filesystem image can contain bogus length. There conditions are
not kernel bugs that can justify kernel to panic.
Red Hat
kernel: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2023-53683 [MEDIUM] kernel: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
kernel: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
In the Linux kernel, the following vulnerability has been resolved:
fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()
syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for
crafted filesystem image can contain bogus length. There conditions are
not kernel bugs that can justify kernel to panic.
A robustness flaw was found in the Linux kernel Hierarchical File System Plus file system in the way inode records are validated when reading or writing catalog entries. Crafted images can provide invalid lengths that trigger kernel warnings intended for internal errors. A local user could use this flaw to provoke warnings and disrupt file system operations, resulting in a denial of service.
Debian
CVE-2023-53683: linux - In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus...
vendor_debian·2023·CVSS 5.5
CVE-2023-53683 [MEDIUM] CVE-2023-53683: linux - In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus...
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are not kernel bugs that can justify kernel to panic.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/37cab61a52d6f42b2d961c51bcf369f09e235fb5https://git.kernel.org/stable/c/3a9d68d84b2e41ba3f2a727b36f035fad6800492https://git.kernel.org/stable/c/48960a503fcec76d3f72347b7e679dda08ca43behttps://git.kernel.org/stable/c/61af77acd039ffd221bf7adf0dc95d0a4d377505https://git.kernel.org/stable/c/81b21c0f0138ff5a499eafc3eb0578ad2a99622chttps://git.kernel.org/stable/c/a75d9211a07fed513c08c5d4861c4a36ac6a74fehttps://git.kernel.org/stable/c/c074913b12db3632b11588b31bbfb0fa80a0a1c9https://git.kernel.org/stable/c/c8daee66585897a4c90d937c91e762100237bff9
2025-10-07
Published