PT-2025-43093 · Ext4+2 · Ext4+2

Published

2023-04-28

·

Updated

2025-12-04

·

CVE-2023-53692

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.2.0-rc1-syzkaller
Description The Linux kernel contains a flaw within the ext4 filesystem implementation. Specifically, a use-after-free condition can occur in the ext4 find extent function when big allocation and inline data features are enabled. This issue arises when inline data is converted to an extent before write operations, leading to a scenario where the EXT4 STATE MAY INLINE DATA flag is not set, but i data still holds inline data. This can trigger a use-after-free when attempting to find the extent. The issue was identified by Syzbot. The ext4 clu mapped function is involved in this issue, and a prior commit (131294c35ed6) addressed a similar delayed allocation bug, but did not fully resolve the problem in this specific scenario.
Recommendations Update to a newer version of the Linux kernel that contains a fix for this vulnerability.

Exploit

Fix

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03793
CVE-2023-53692
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4320-1

Affected Products

Linux Kernel
Suse
Ext4