-

CVE-2023-53450

In the Linux kernel, the following vulnerability has been resolved:

ext4: remove a BUG_ON in ext4_mb_release_group_pa()

If a malicious fuzzer overwrites the ext4 superblock while it is
mounted such that the s_first_data_block is set to a very large
number, the calculation of the block group can underflow, and trigger
a BUG_ON check.  Change this to be an ext4_warning so that we don't
crash the kernel.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < d5bf8f7fb3ee3d99d1303ceb54599ea0599a4a5b
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < ef16d8a1798db1a1604ac44ca1bd73ec6bebf483
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 185062a21976fbc38f2efd296951b02c4500cf65
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < b0fc279de4bf17e1710bb7e83906538ff8f11111
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 978e5e9111af18741449b81fefd531a622dd969a
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < d87a4e4094c9879fc8acdff8ce59fdffa979c8e0
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < bf2a16eb4e6d06124bd8436d4546f61539a65f29
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 53c14e7cc2257191ba15425c15638fc4f8abb92b
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
Version < 463808f237cf73e98a1a45ff7460c2406a150a0b
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version <= 4.14.*
Version 4.14.315
Status unaffected
Version <= 4.19.*
Version 4.19.283
Status unaffected
Version <= 5.4.*
Version 5.4.243
Status unaffected
Version <= 5.10.*
Version 5.10.180
Status unaffected
Version <= 5.15.*
Version 5.15.112
Status unaffected
Version <= 6.1.*
Version 6.1.29
Status unaffected
Version <= 6.2.*
Version 6.2.16
Status unaffected
Version <= 6.3.*
Version 6.3.3
Status unaffected
Version <= *
Version 6.4
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.129
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string