PT-2025-40210 · Ext4+2 · Ext4+2

Published

2023-04-29

·

Updated

2025-10-02

·

CVE-2023-53503

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the ext4 filesystem implementation. Specifically, the ext4 get group info() function previously triggered a kernel BUG when encountering an invalid group number, potentially leading to a denial of service. This condition could be induced by modifying the superblock via the block device while the filesystem is mounted, resulting in an underflow and a large block group number. The function has been modified to return NULL instead of triggering a BUG, and callers have been updated to handle this possibility. The function was also un-inlined to reduce compiled text size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

NULL Pointer Dereference

Integer Underflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-12822
CVE-2023-53503
RHSA-2024:10771
RHSA-2024:9315
RHSA-2024_9315

Affected Products

Linux Kernel
Red Hat
Ext4