CVE-2023-53285

HIGH

Linux Kernel < 4.14.315 - Out-of-Bounds Read in ext4 Inline Xattr Value Size Calculation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extended attributes in the inode body would have been checked when the inode is first opened, but if someone is writing to the block device while the file system is mounted, it's possible for the inode table to get corrupted. Add bounds checking to avoid reading beyond the end of allocated memory if this happens.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (30)
linux/Kernel 3.8.0 - 4.14.315linux
linux/Kernel 4.15.0 - 4.19.283linux
linux/Kernel 4.20.0 - 5.4.243linux
linux/Kernel 5.11.0 - 5.15.112linux
linux/Kernel 5.16.0 - 6.1.29linux
linux/Kernel 5.5.0 - 5.10.180linux
linux/Kernel 6.2.0 - 6.2.16linux
linux/Kernel 6.3.0 - 6.3.3linux
Linux/Linux < 3.8
Linux/Linux 3.8
... and 20 more
Published Sep 16, 2025
Tracked Since Feb 18, 2026