CVE-2023-53506
HIGHLinux Kernel 2.6.12.1-6.2.2 - Extent Corruption via UDF Merging
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: udf: Do not bother merging very long extents When merging very long extents we try to push as much length as possible to the first extent. However this is unnecessarily complicated and not really worth the trouble. Furthermore there was a bug in the logic resulting in corrupting extents in the file as syzbot reproducer shows. So just don't bother with the merging of extents that are too long together.
References (8)
Core 8
Core References
Scores
CVSS v3
7.8
EPSS
0.0015
EPSS Percentile
5.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (27)
linux/Kernel
2.6.12 - 4.14.308linux
linux/Kernel
4.15.0 - 4.19.276linux
linux/Kernel
4.20.0 - 5.4.235linux
linux/Kernel
5.11.0 - 5.15.99linux
linux/Kernel
5.16.0 - 6.1.16linux
linux/Kernel
5.5.0 - 5.10.173linux
linux/Kernel
6.2.0 - 6.2.3linux
Linux/Linux
< 2.6.12
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 3d20e3b768aff32112bdce8d3219d923ae75f9f1
Linux/Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 53cafe1d6d8ef9f93318e5bfccc0d24f27d41ced
... and 17 more
Published
Oct 01, 2025
Tracked Since
Feb 18, 2026