{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53695","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-10-22T13:21:37.344Z","datePublished":"2025-10-22T13:23:36.524Z","dateUpdated":"2026-08-05T09:15:35.101Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:15:35.101Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Detect system inodes linked into directory hierarchy\n\nWhen UDF filesystem is corrupted, hidden system inodes can be linked\ninto directory hierarchy which is an avenue for further serious\ncorruption of the filesystem and kernel confusion as noticed by syzbot\nfuzzed images. Refuse to access system inodes linked into directory\nhierarchy and vice versa."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires a crafted UDF filesystem image to be mounted on the target and then accessed through ordinary local filesystem syscalls (lookup, open, unlink, write, truncate). There is no network-facing path into fs/udf.\nAC:L - The attacker fully controls the on-disk image and simply points a directory entry at the same block as a hidden system inode (VAT/metadata/mirror/bitmap FE), which deterministically returns the cached hidden inode from iget_locked() with the link-count-0 check bypassed. The follow-on races against the unlocked udf_try_read_meta()/inode_bmap() walk are also attacker-driven from two of the attacker's own threads.\nPR:L - udf is FS_REQUIRES_DEV without FS_USERNS_MOUNT, but the realistic delivery is a low-privileged local user's removable disc/USB/ISO auto-mounted by udisks2 on desktops, kiosks and shared workstations; every subsequent step (open, unlink, ftruncate, write on the exposed system inode) needs only ordinary unprivileged file access.\nUI:N - In the auto-mount scenario the attacker inserts the media and performs all filesystem operations themselves, so no separate victim action is required.\nS:U - The corruption and crash stay within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Exposing a system inode as a normal file lets the attacker mutate its extent list while udf_try_read_meta() walks it with no i_data_sem held, yielding out-of-bounds reads past the i_data kmalloc buffer and parsing of freed/reallocated blocks, so kernel heap contents can be surfaced through ordinary file reads.\nI:H - The same inode is simultaneously the kernel's internal block-translation table and a user-writable file, so writes and truncates rewrite in-use metadata mappings, and udf_free_inode()/udf_free_blocks() releases blocks the superblock is still using — unsynchronized modification of live kernel filesystem state that is exploitable for further memory corruption.\nA:H - syzbot reproduced a kernel WARNING in udf_free_inode() via udf_evict_inode() (udf_updated_lvid, which also carries a BUG_ON), which panics under panic_on_warn, and the resulting metadata-mapping corruption cascades into further oopses."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/udf/inode.c"],"versions":[{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"1dc71eeb198a8daa17d0c995998a53b0b749a158","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"d747b31e2925a2f384e7dd1901a2e5bc5f984ed8","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"a44ec34b90440ada190924f5908b97026504fdcd","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"37e74003d81e79457535cbbdfa1603431c03fac0","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"1f328751b65c49c13a312d67a3bf27766b85baf7","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"9e3b5ef7d02eaa6553e79b4af9bd99227280f245","status":"affected","versionType":"git"},{"version":"6174c2eb8ecef271159bdcde460ce8af54d8f72f","lessThan":"85a37983ec69cc9fcd188bc37c4de15ee326355a","status":"affected","versionType":"git"},{"version":"801c7a20d255e300ab51a6fcb1d0e218d136b16f","status":"affected","versionType":"git"},{"version":"3.17.2","lessThan":"3.18","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/udf/inode.c"],"versions":[{"version":"3.18","status":"affected"},{"version":"0","lessThan":"3.18","status":"unaffected","versionType":"semver"},{"version":"4.19.278","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.235","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.173","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.99","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.16","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.3","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"4.19.278"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"5.4.235"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"5.10.173"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"5.15.99"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"6.1.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"6.2.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18","versionEndExcluding":"6.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.17.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1dc71eeb198a8daa17d0c995998a53b0b749a158"},{"url":"https://git.kernel.org/stable/c/d747b31e2925a2f384e7dd1901a2e5bc5f984ed8"},{"url":"https://git.kernel.org/stable/c/a44ec34b90440ada190924f5908b97026504fdcd"},{"url":"https://git.kernel.org/stable/c/37e74003d81e79457535cbbdfa1603431c03fac0"},{"url":"https://git.kernel.org/stable/c/1f328751b65c49c13a312d67a3bf27766b85baf7"},{"url":"https://git.kernel.org/stable/c/9e3b5ef7d02eaa6553e79b4af9bd99227280f245"},{"url":"https://git.kernel.org/stable/c/85a37983ec69cc9fcd188bc37c4de15ee326355a"}],"title":"udf: Detect system inodes linked into directory hierarchy","x_generator":{"engine":"bippy-1.2.0"}}}}