CVE-2023-53695
In the Linux kernel, the following vulnerability has been resolved: udf: Detect system inodes linked into directory hierarchy When UDF filesystem is corrupted, hidden system inodes can be linked into directory hierarchy which is an avenue for further…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: udf: Detect system inodes linked into directory hierarchy When UDF filesystem is corrupted, hidden system inodes can be linked into directory hierarchy which is an avenue for further serious corruption of the filesystem and kernel confusion as noticed by syzbot fuzzed images. Refuse to access system inodes linked into directory hierarchy and vice versa.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.15% probability · 5th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1dc71eeb198a8daa17d0c995998a53b0b749a158
- https://git.kernel.org/stable/c/1f328751b65c49c13a312d67a3bf27766b85baf7
- https://git.kernel.org/stable/c/37e74003d81e79457535cbbdfa1603431c03fac0
- https://git.kernel.org/stable/c/85a37983ec69cc9fcd188bc37c4de15ee326355a
- https://git.kernel.org/stable/c/9e3b5ef7d02eaa6553e79b4af9bd99227280f245
- https://git.kernel.org/stable/c/a44ec34b90440ada190924f5908b97026504fdcd
- https://git.kernel.org/stable/c/d747b31e2925a2f384e7dd1901a2e5bc5f984ed8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.