Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-345173
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 08:00
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T08:00:19.198417+00:00",
"id": "EUVD-2026-345173"
}
CVE-2023-53285 (GCVE-0-2023-53285)
Vulnerability from cvelistv5 – Published: 2025-09-16 08:11 – Updated: 2026-08-05 09:13
VLAI
EPSS
VEX
Title
ext4: add bounds checking in get_max_inline_xattr_value_size()
Summary
In the Linux kernel, the following vulnerability has been resolved:
ext4: add bounds checking in get_max_inline_xattr_value_size()
Normally the extended attributes in the inode body would have been
checked when the inode is first opened, but if someone is writing to
the block device while the file system is mounted, it's possible for
the inode table to get corrupted. Add bounds checking to avoid
reading beyond the end of allocated memory if this happens.
Severity
7.1 (High)
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-01-14 18:09 UTC
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
67cf5b09a46f72e048501b84996f2f77bc42e947 , < 5a229d21b98d132673096710e8281ef522dab1d1
(git)
Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205 (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 486efbbc9445dca7890a1b86adbccb88b91284b0 (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 4597554b4f7b29e7fd78aa449bab648f8da4ee2c (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < f22b274429e88d3dc7e79d375b56ce4f2f59f0b4 (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < e780058bd75614b66882bc02620ddbd884171560 (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 88a06a94942c5c0a896e9da1113a6bb29e36cbef (git) Affected: 67cf5b09a46f72e048501b84996f2f77bc42e947 , < 2220eaf90992c11d888fe771055d4de330385f01 (git) |
|
| Linux | Linux |
Affected:
3.8
Unaffected: 0 , < 3.8 (semver) Unaffected: 4.14.315 , ≤ 4.14.* (semver) Unaffected: 4.19.283 , ≤ 4.19.* (semver) Unaffected: 5.4.243 , ≤ 5.4.* (semver) Unaffected: 5.10.180 , ≤ 5.10.* (semver) Unaffected: 5.15.112 , ≤ 5.15.* (semver) Unaffected: 6.1.29 , ≤ 6.1.* (semver) Unaffected: 6.2.16 , ≤ 6.2.* (semver) Unaffected: 6.3.3 , ≤ 6.3.* (semver) Unaffected: 6.4 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-53285",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-01-14T18:09:24.423172Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "CWE-noinfo Not enough information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-01-14T18:12:55.248Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/ext4/inline.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a229d21b98d132673096710e8281ef522dab1d1",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "486efbbc9445dca7890a1b86adbccb88b91284b0",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "4597554b4f7b29e7fd78aa449bab648f8da4ee2c",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "f22b274429e88d3dc7e79d375b56ce4f2f59f0b4",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "e780058bd75614b66882bc02620ddbd884171560",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "88a06a94942c5c0a896e9da1113a6bb29e36cbef",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
},
{
"lessThan": "2220eaf90992c11d888fe771055d4de330385f01",
"status": "affected",
"version": "67cf5b09a46f72e048501b84996f2f77bc42e947",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/ext4/inline.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"lessThan": "3.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.315",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.283",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.243",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.180",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.112",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.29",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.2.*",
"status": "unaffected",
"version": "6.2.16",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.3.*",
"status": "unaffected",
"version": "6.3.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.4",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.315",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.283",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.243",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.180",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.112",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.29",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.2.16",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.3",
"versionStartIncluding": "3.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.4",
"versionStartIncluding": "3.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: add bounds checking in get_max_inline_xattr_value_size()\n\nNormally the extended attributes in the inode body would have been\nchecked when the inode is first opened, but if someone is writing to\nthe block device while the file system is mounted, it\u0027s possible for\nthe inode table to get corrupted. Add bounds checking to avoid\nreading beyond the end of allocated memory if this happens."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached through the local VFS write path (write \u2192 ext4_write_begin \u2192 ext4_try_to_write_inline_data \u2192 ext4_get_max_inline_size \u2192 get_max_inline_xattr_value_size) on a mounted ext4 volume; there is no network or remote-protocol entry point.\nAC:L - A crafted ext4 image (and, as the fix notes, inode-table corruption via attacker-controlled writes to the underlying loop/block device while mounted) deterministically drives the unbounded xattr walk; the attacker controls both the image and the triggering write with no uncontrollable race.\nPR:L - An unprivileged local user can mount an attacker-authored ext4 image via common desktop/kiosk loop-setup paths (e.g. udisks2 polkit allow_active) and then write to a file on that mount; real init-namespace root is not required.\nUI:N - In the loop/automount scenario the attacker performs the mount and the triggering write themselves; no separate victim action is required.\nS:U - The OOB read and any resulting oops remain inside the host kernel\u0027s ext4/VFS authority and do not cross a VM, IOMMU, or sandbox boundary.\nC:H - The unfixed walk follows EXT4_XATTR_NEXT without an end bound, so it performs an unbounded out-of-bounds read past the inode buffer into adjacent kernel heap (KASAN slab-OOB/UAF Read, including into freed objects such as skbuff), which scores Confidentiality High under OOB-read guidance.\nI:N - The vulnerable function only reads xattr entry headers to compute a size; the fixed defect is a pure OOB read with no OOB write, reclaimable UAF write, or other integrity/control-flow primitive.\nA:H - Reading past the inode allocation into invalid/freed memory produces a kernel oops (as in the syzbot KASAN reports), which is a full availability impact under kernel CVSS guidance."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T09:13:22.549Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a229d21b98d132673096710e8281ef522dab1d1"
},
{
"url": "https://git.kernel.org/stable/c/3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205"
},
{
"url": "https://git.kernel.org/stable/c/486efbbc9445dca7890a1b86adbccb88b91284b0"
},
{
"url": "https://git.kernel.org/stable/c/4597554b4f7b29e7fd78aa449bab648f8da4ee2c"
},
{
"url": "https://git.kernel.org/stable/c/f22b274429e88d3dc7e79d375b56ce4f2f59f0b4"
},
{
"url": "https://git.kernel.org/stable/c/1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f"
},
{
"url": "https://git.kernel.org/stable/c/e780058bd75614b66882bc02620ddbd884171560"
},
{
"url": "https://git.kernel.org/stable/c/88a06a94942c5c0a896e9da1113a6bb29e36cbef"
},
{
"url": "https://git.kernel.org/stable/c/2220eaf90992c11d888fe771055d4de330385f01"
}
],
"title": "ext4: add bounds checking in get_max_inline_xattr_value_size()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2023-53285",
"datePublished": "2025-09-16T08:11:18.585Z",
"dateReserved": "2025-09-16T08:09:37.991Z",
"dateUpdated": "2026-08-05T09:13:22.549Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…