Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53450— ext4: remove a BUG_ON in ext4_mb_release_group_pa()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于块组计算可能发生整数下溢,可能导致内核崩溃。

AI Predicted 4.4 Difficulty: Theoretical EPSS 0.15% · P5

Possible ATT&CK Techniques 1 AI

T1055 · Process Injection

Affected Version Matrix 20

VendorProduct Version RangeStatus
Linux Linux c9de560ded61faa5b754137b7753da252391c55a< d5bf8f7fb3ee3d99d1303ceb54599ea0599a4a5b affected
c9de560ded61faa5b754137b7753da252391c55a< ef16d8a1798db1a1604ac44ca1bd73ec6bebf483 affected
c9de560ded61faa5b754137b7753da252391c55a< 185062a21976fbc38f2efd296951b02c4500cf65 affected
c9de560ded61faa5b754137b7753da252391c55a< b0fc279de4bf17e1710bb7e83906538ff8f11111 affected
c9de560ded61faa5b754137b7753da252391c55a< 978e5e9111af18741449b81fefd531a622dd969a affected
c9de560ded61faa5b754137b7753da252391c55a< d87a4e4094c9879fc8acdff8ce59fdffa979c8e0 affected
c9de560ded61faa5b754137b7753da252391c55a< bf2a16eb4e6d06124bd8436d4546f61539a65f29 affected
c9de560ded61faa5b754137b7753da252391c55a< 53c14e7cc2257191ba15425c15638fc4f8abb92b affected
… +12 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-53450

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ext4: remove a BUG_ON in ext4_mb_release_group_pa()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: remove a BUG_ON in ext4_mb_release_group_pa() If a malicious fuzzer overwrites the ext4 superblock while it is mounted such that the s_first_data_block is set to a very large number, the calculation of the block group can underflow, and trigger a BUG_ON check. Change this to be an ext4_warning so that we don't crash the kernel.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于块组计算可能发生整数下溢,可能导致内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c9de560ded61faa5b754137b7753da252391c55a ~ d5bf8f7fb3ee3d99d1303ceb54599ea0599a4a5b -
Linux Linux 2.6.25 -

II. Public POCs for CVE-2023-53450

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53450

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-10-01 · 169 CVEs total

CVE-2023-53517 9.8 CRITICAL tipc: do not update mtu if msg_max is too small in mtu negotiation
CVE-2023-53454 8.8 HIGH HID: multitouch: Correct devm device reference for hidinput input_dev name
CVE-2025-39918 8.8 HIGH wifi: mt76: fix linked list corruption
CVE-2025-39919 8.8 HIGH wifi: mt76: mt7996: add missing check for rx wcid entries
CVE-2022-50442 8.4 HIGH fs/ntfs3: Validate buffer length while parsing index
CVE-2023-53493 8.4 HIGH accel/qaic: tighten bounds checking in decode_message()
CVE-2023-53465 7.8 HIGH soundwire: qcom: fix storing port config out-of-bounds
CVE-2023-53485 7.8 HIGH fs: jfs: Fix UBSAN: array-index-out-of-bounds in dbAllocDmapLev
CVE-2022-50440 7.8 HIGH drm/vmwgfx: Validate the box size for the snooped cursor
CVE-2022-50454 7.8 HIGH drm/nouveau: fix a use-after-free in nouveau_gem_prime_import_sg_table()
CVE-2025-39924 7.8 HIGH erofs: fix invalid algorithm for encoded extents
CVE-2023-53510 7.8 HIGH scsi: ufs: core: Fix handling of lrbp->cmd
CVE-2025-39927 7.8 HIGH ceph: fix race condition validating r_parent before applying state
CVE-2023-53506 7.8 HIGH udf: Do not bother merging very long extents
CVE-2022-50421 7.8 HIGH rpmsg: char: Avoid double destroy of default endpoint
CVE-2022-50437 7.8 HIGH drm/msm/hdmi: fix memory corruption with too many bridges
CVE-2023-53495 7.8 HIGH net: ethernet: mvpp2_main: fix possible OOB write in mvpp2_ethtool_get_rxnfc()
CVE-2023-53494 7.8 HIGH crypto: xts - Handle EBUSY correctly
CVE-2022-50432 7.8 HIGH kernfs: fix use-after-free in __kernfs_remove
CVE-2023-53492 7.8 HIGH netfilter: nf_tables: do not ignore genmask when looking up chain by id

Showing top 20 of 169 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53450

No comments yet


Leave a comment