NONE · 0

CVE-2023-54119

In the Linux kernel, the following vulnerability has been resolved: inotify: Avoid reporting event with invalid wd When inotify_freeing_mark() races with inotify_handle_inode_event() it can happen t...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: inotify: Avoid reporting event with invalid wd When inotify_freeing_mark() races with inotify_handle_inode_event() it can happen that inotify_handle_inode_event() sees that i_mark->wd got already reset to -1 and reports this value to userspace which can confuse the inotify listener. Avoid the problem by validating that wd is sensible (and pretend the mark got removed before the event got generated otherwise).

References

FAQ

What is CVE-2023-54119?

CVE-2023-54119 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: inotify: Avoid reporting event with invalid wd When inotify_freeing_mark() races with inotify_handle_inode_event() it can happen t...

How severe is CVE-2023-54119?

CVSS scoring is not yet available for CVE-2023-54119. Check NVD for updates.

Is there a patch for CVE-2023-54119?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.