CVE-2023-53683
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length.
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are not kernel bugs that can justify kernel to panic.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.15% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/37cab61a52d6f42b2d961c51bcf369f09e235fb5Patch
- https://git.kernel.org/stable/c/3a9d68d84b2e41ba3f2a727b36f035fad6800492Patch
- https://git.kernel.org/stable/c/48960a503fcec76d3f72347b7e679dda08ca43bePatch
- https://git.kernel.org/stable/c/61af77acd039ffd221bf7adf0dc95d0a4d377505Patch
- https://git.kernel.org/stable/c/81b21c0f0138ff5a499eafc3eb0578ad2a99622cPatch
- https://git.kernel.org/stable/c/a75d9211a07fed513c08c5d4861c4a36ac6a74fePatch
- https://git.kernel.org/stable/c/c074913b12db3632b11588b31bbfb0fa80a0a1c9Patch
- https://git.kernel.org/stable/c/c8daee66585897a4c90d937c91e762100237bff9Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.