PT-2025-43093 · Ext4+2 · Ext4+2
Published
2023-04-28
·
Updated
2025-12-04
·
CVE-2023-53692
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.2.0-rc1-syzkaller
Description
The Linux kernel contains a flaw within the ext4 filesystem implementation. Specifically, a use-after-free condition can occur in the
ext4 find extent function when big allocation and inline data features are enabled. This issue arises when inline data is converted to an extent before write operations, leading to a scenario where the EXT4 STATE MAY INLINE DATA flag is not set, but i data still holds inline data. This can trigger a use-after-free when attempting to find the extent. The issue was identified by Syzbot. The ext4 clu mapped function is involved in this issue, and a prior commit (131294c35ed6) addressed a similar delayed allocation bug, but did not fully resolve the problem in this specific scenario.Recommendations
Update to a newer version of the Linux kernel that contains a fix for this vulnerability.
Exploit
Fix
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Suse
Ext4