{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53626","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-10-07T15:16:59.656Z","datePublished":"2025-10-07T15:19:30.895Z","dateUpdated":"2026-08-05T09:15:11.541Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:15:11.541Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix possible double unlock when moving a directory"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the `rename(2)` syscall on a locally mounted ext4 filesystem; no network or remote peer is involved. The attacker needs local access to mount/attach the crafted ext4 image and issue the rename.\nAC:L - The `ext4_rename_dir_prepare()` failure is deterministic with a crafted `.`/`..` entry, so the double `up_write()` always occurs, and the attacker controls every thread contending for the moved directory's `i_rwsem`. The unlock window spans a sleeping `ext4_journal_stop()`, so winning the mutual-exclusion-break race is easy and infinitely retryable.\nPR:L - An ordinary unprivileged local user suffices: on mainstream desktop/kiosk deployments udisks2's default polkit `allow_active` loop-setup and removable-media automount let a console user mount an arbitrary attacker-authored ext4 image, and the `rename(2)` itself needs only write access to the attacker's own directories.\nUI:N - In the automount/loop-setup scenario the attacker performs the mount and the rename themselves; no second user has to be induced into any action.\nS:U - The corrupted `i_rwsem`, the resulting concurrent directory mutation, and any memory corruption all stay within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Breaking exclusion on a directory inode lets concurrent readers/writers race the inline-dir-to-extent conversion, so dirent parsing runs against the raw inode's `i_block`/xattr region under a stale format assumption, exposing adjacent kernel memory through `readdir`/`getdents`, and the buffer_head UAF this enables gives a further read primitive.\nI:H - The silent release of another task's exclusive `i_rwsem` allows two threads to run ext4 dirent add/delete, htree split, and inline-to-extent conversion on the same inode simultaneously, producing metadata and heap corruption — the exact corruption class `0813299c586b` was written to prevent — which is leverageable for controlled writes.\nA:H - When the lock is free at the second unlock, the rwsem count underflows to `~0UL` with no owner, so every later `down_read`/`down_write` on that directory blocks permanently in uninterruptible sleep, hanging the directory, the unmount, and eventually tripping the hung-task watchdog. The corruption path independently yields oopses and `errors=remount-ro`/`panic` filesystem shutdown."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext4/namei.c"],"versions":[{"version":"8dac5a63cf79707b547ea3d425fead5f4482198f","lessThan":"c16cbd8233d6c58fc488545393e49b5d55729990","status":"affected","versionType":"git"},{"version":"0c440f14558bfacd22c6935ae1fd4b2a09e96b5d","lessThan":"020166bc6669ca9fb267ebd96bd88c4fb64a5d46","status":"affected","versionType":"git"},{"version":"c50fc503ee1b97f12c98e26afc39fdaebebcf04f","lessThan":"1c93c42c7bb23057bde8a0a2ab834927ff64d20c","status":"affected","versionType":"git"},{"version":"b0bb13612292ca90fa4c2a7e425375649bc50d3e","lessThan":"e71eb4dca41f0f36823724ced0406bb2dbdd5506","status":"affected","versionType":"git"},{"version":"291cd19d107e197306869cb3237c1bba62d13182","lessThan":"43ce288ab5d7274a4a141d7f5e3ed2ab7b41f8a2","status":"affected","versionType":"git"},{"version":"0813299c586b175d7edb25f56412c54b812d0379","lessThan":"70e42feab2e20618ddd0cbfc4ab4b08628236ecd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ext4/namei.c"],"versions":[{"version":"5.4.237","lessThan":"5.4.238","status":"affected","versionType":"semver"},{"version":"5.10.175","lessThan":"5.10.176","status":"affected","versionType":"semver"},{"version":"5.15.103","lessThan":"5.15.104","status":"affected","versionType":"semver"},{"version":"6.1.20","lessThan":"6.1.21","status":"affected","versionType":"semver"},{"version":"6.2.7","lessThan":"6.2.8","status":"affected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.237","versionEndExcluding":"5.4.238"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.175","versionEndExcluding":"5.10.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.103","versionEndExcluding":"5.15.104"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.20","versionEndExcluding":"6.1.21"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.7","versionEndExcluding":"6.2.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c16cbd8233d6c58fc488545393e49b5d55729990"},{"url":"https://git.kernel.org/stable/c/020166bc6669ca9fb267ebd96bd88c4fb64a5d46"},{"url":"https://git.kernel.org/stable/c/1c93c42c7bb23057bde8a0a2ab834927ff64d20c"},{"url":"https://git.kernel.org/stable/c/e71eb4dca41f0f36823724ced0406bb2dbdd5506"},{"url":"https://git.kernel.org/stable/c/43ce288ab5d7274a4a141d7f5e3ed2ab7b41f8a2"},{"url":"https://git.kernel.org/stable/c/70e42feab2e20618ddd0cbfc4ab4b08628236ecd"}],"title":"ext4: fix possible double unlock when moving a directory","x_generator":{"engine":"bippy-1.2.0"}}}}