CVE-2023-53285
HIGHLinux Kernel < 4.14.315 - Out-of-Bounds Read in ext4 Inline Xattr Value Size Calculation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_value_size() Normally the extended attributes in the inode body would have been checked when the inode is first opened, but if someone is writing to the block device while the file system is mounted, it's possible for the inode table to get corrupted. Add bounds checking to avoid reading beyond the end of allocated memory if this happens.
References (9)
Core 9
Core References
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
4.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
Status
published
Products (30)
linux/Kernel
3.8.0 - 4.14.315linux
linux/Kernel
4.15.0 - 4.19.283linux
linux/Kernel
4.20.0 - 5.4.243linux
linux/Kernel
5.11.0 - 5.15.112linux
linux/Kernel
5.16.0 - 6.1.29linux
linux/Kernel
5.5.0 - 5.10.180linux
linux/Kernel
6.2.0 - 6.2.16linux
linux/Kernel
6.3.0 - 6.3.3linux
Linux/Linux
< 3.8
Linux/Linux
3.8
... and 20 more
Published
Sep 16, 2025
Tracked Since
Feb 18, 2026