ext4: add bounds checking in get_max_inline_xattr_value_size()
Published Sep 16, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
Normally the extended attributes in the inode body would have been checked when the inode is first opened, but if someone is writing to the block device while the file system is mounted, it's possible for the inode table to get corrupted. Add bounds checking to avoid reading beyond the end of allocated memory if this happens.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.8StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.8
- Version 4.14.315StatusunaffectedConstraints<=4.14.*
- Version 4.19.283StatusunaffectedConstraints<=4.19.*
- Version 5.10.180StatusunaffectedConstraints<=5.10.*
- Version 5.15.112StatusunaffectedConstraints<=5.15.*
- Version 5.4.243StatusunaffectedConstraints<=5.4.*
- Version 6.1.29StatusunaffectedConstraints<=6.1.*
- Version 6.2.16StatusunaffectedConstraints<=6.2.*
- Version 6.3.3StatusunaffectedConstraints<=6.3.*
- Version 6.4StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.14.315
- ≥ 4.15 · < 4.19.283
- ≥ 4.20 · < 5.4.243
- ≥ 5.5 · < 5.10.180
- ≥ 5.11 · < 5.15.112
- ≥ 5.16 · < 6.1.29
- ≥ 6.2 · < 6.2.16
- ≥ 6.3 · < 6.3.3
- 6.4
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.16% (0.00156) | 4.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.14% (0.00145) | 4.12th | v5 (v2026.06.15) |
| Sep 16, 2025 | 0.03% (0.00033) | 7.99th | v4 (v2025.03.14) |
References (14)
- https://access.redhat.com/security/cve/CVE-2023-53285 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395666 Issue Tracking
- https://git.kernel.org/stable/c/1d2caddbeeee56fbbc36b428c5b909c3ad88eb7f Patch
- https://git.kernel.org/stable/c/2220eaf90992c11d888fe771055d4de330385f01 Patch
- https://git.kernel.org/stable/c/3d7b8fbcd2273e2b9f4c6de5ce2f4c0cd3cb1205 Patch
- https://git.kernel.org/stable/c/4597554b4f7b29e7fd78aa449bab648f8da4ee2c Patch
- https://git.kernel.org/stable/c/486efbbc9445dca7890a1b86adbccb88b91284b0 Patch
- https://git.kernel.org/stable/c/5a229d21b98d132673096710e8281ef522dab1d1 Patch
- https://git.kernel.org/stable/c/88a06a94942c5c0a896e9da1113a6bb29e36cbef Patch
- https://git.kernel.org/stable/c/e780058bd75614b66882bc02620ddbd884171560 Patch
- https://git.kernel.org/stable/c/f22b274429e88d3dc7e79d375b56ce4f2f59f0b4 Patch
- https://lore.kernel.org/linux-cve-announce/2025091625-CVE-2023-53285-7cb1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53285
- https://www.cve.org/CVERecord?id=CVE-2023-53285
Change history (0)
No recorded changes yet.