Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are not kernel bugs that can justify kernel to panic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.14.303, < 4.14.316 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/37cab61a52d6f42b2d961c51bcf369f09e235fb5Patch
- https://git.kernel.org/stable/c/3a9d68d84b2e41ba3f2a727b36f035fad6800492Patch
- https://git.kernel.org/stable/c/48960a503fcec76d3f72347b7e679dda08ca43bePatch
- https://git.kernel.org/stable/c/61af77acd039ffd221bf7adf0dc95d0a4d377505Patch
- https://git.kernel.org/stable/c/81b21c0f0138ff5a499eafc3eb0578ad2a99622cPatch
- https://git.kernel.org/stable/c/a75d9211a07fed513c08c5d4861c4a36ac6a74fePatch
- https://git.kernel.org/stable/c/c074913b12db3632b11588b31bbfb0fa80a0a1c9Patch
- https://git.kernel.org/stable/c/c8daee66585897a4c90d937c91e762100237bff9Patch
FAQ
What is CVE-2023-53683?
CVE-2023-53683 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(...
How severe is CVE-2023-53683?
CVE-2023-53683 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53683?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.