fsverity: reject FS_IOC_ENABLE_VERITY on mode 3 fds
Published Sep 15, 2025
5.8
MEDIUMCVSS 3.1
EPSS 0.14%
Description
Commit 56124d6c87fd ("fsverity: support enabling with tree block size < PAGE_SIZE") changed FS_IOC_ENABLE_VERITY to use __kernel_read() to read the file's data, instead of direct pagecache accesses.
An unintended consequence of this is that the 'WARN_ON_ONCE(!(file->f_mode & FMODE_READ))' in __kernel_read() became reachable by fuzz tests. This happens if FS_IOC_ENABLE_VERITY is called on a fd opened with access mode 3, which means "ioctl access only".
Arguably, FS_IOC_ENABLE_VERITY should work on ioctl-only fds. But ioctl-only fds are a weird Linux extension that is rarely used and that few people even know about. (The documentation for FS_IOC_ENABLE_VERITY even specifically says it requires O_RDONLY.) It's probably not worthwhile to make the ioctl internally open a new fd just to handle this case. Thus, just reject the ioctl on such fds for now.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.3StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.3
- Version 6.3.1StatusunaffectedConstraints<=6.3.*
- Version 6.4StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- 6.3
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-53172 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395291 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59804 Advisory
- https://git.kernel.org/stable/c/04839139213cf60d4c5fc792214a08830e294ff8 Patch
- https://git.kernel.org/stable/c/85c039cff3c359967cafe90443c02321e950b216 Patch
- https://lore.kernel.org/linux-cve-announce/2025091554-CVE-2023-53172-3f93@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53172
- https://www.cve.org/CVERecord?id=CVE-2023-53172
Change history (0)
No recorded changes yet.