Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53672— btrfs: output extra debug info if we failed to find an inline backref

EPSS 0.14% · P3

Possible ATT&CK Techniques 1AI

T1083 · File and Directory Discovery

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux492104c866cb1b62a11393adccb477f5cd2c7768< 376b41524b71e494514720bd6114325b0a2ed19caffected
492104c866cb1b62a11393adccb477f5cd2c7768< 400e08a16604b534fdd82c5a288fa150d04f5f79affected
492104c866cb1b62a11393adccb477f5cd2c7768< 7afbfde45d665953b4d5a42a721e15bf0315d89baffected
492104c866cb1b62a11393adccb477f5cd2c7768< b7c3cf2f6c42e6688b1c37215a0b1663f982f915affected
492104c866cb1b62a11393adccb477f5cd2c7768< 6994f806c6d1ae8b59344d3700358547f3b3fe1daffected
492104c866cb1b62a11393adccb477f5cd2c7768< 28062cd6eda04035d8f6ded2001292ac8b496149affected
492104c866cb1b62a11393adccb477f5cd2c7768< e70ba449b04b40584bdabb383d10455397cbf177affected
492104c866cb1b62a11393adccb477f5cd2c7768< 7f72f50547b7af4ddf985b07fc56600a4deba281affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
btrfs: output extra debug info if we failed to find an inline backref
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: output extra debug info if we failed to find an inline backref [BUG] Syzbot reported several warning triggered inside lookup_inline_extent_backref(). [CAUSE] As usual, the reproducer doesn't reliably trigger locally here, but at least we know the WARN_ON() is triggered when an inline backref can not be found, and it can only be triggered when @insert is true. (I.e. inserting a new inline backref, which means the backref should already exist) [ENHANCEMENT] After the WARN_ON(), dump all the parameters and the extent tree leaf to help debug.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于无法找到内联反向引用时缺少额外调试信息,可能导致系统不稳定。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 492104c866cb1b62a11393adccb477f5cd2c7768 ~ 376b41524b71e494514720bd6114325b0a2ed19c -
LinuxLinux 3.9 -

II. Public POCs for CVE-2023-53672

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53672

登录查看更多情报信息。

Patches & Fixes for CVE-2023-53672 (1)

Same Patch Batch · Linux · 2025-10-07 · 118 CVEs total

CVE-2023-536299.8 CRITICALfs: dlm: fix use after free in midcomms commit
CVE-2023-536308.8 HIGHiommufd: Fix unpinning of pages when an access is present
CVE-2023-536768.8 HIGHscsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show()
CVE-2023-536758.8 HIGHscsi: ses: Fix possible desc_ptr out-of-bounds accesses
CVE-2023-536738.8 HIGHBluetooth: hci_event: call disconnect callback before deleting conn
CVE-2023-536798.3 HIGHwifi: mt7601u: fix an integer underflow
CVE-2023-536358.2 HIGHnetfilter: conntrack: fix wrong ct->timeout value
CVE-2023-536697.8 HIGHtcp: fix skb_copy_ubufs() vs BIG TCP
CVE-2022-505557.8 HIGHtipc: fix a null-ptr-deref in tipc_topsrv_accept
CVE-2023-536277.8 HIGHscsi: hisi_sas: Grab sas_dev lock when traversing the members of sas_dev.list
CVE-2023-536267.8 HIGHext4: fix possible double unlock when moving a directory
CVE-2023-536607.8 HIGHbpf, cpumap: Handle skb as well when clean up ptr_ring
CVE-2023-536597.8 HIGHiavf: Fix out-of-bounds when setting channels on remove
CVE-2023-536197.8 HIGHnetfilter: conntrack: Avoid nf_ct_helper_hash uses after free
CVE-2023-536437.8 HIGHnvme-tcp: don't access released socket during error recovery
CVE-2023-536457.8 HIGHbpf: Make bpf_refcount_acquire fallible for non-owning refs
CVE-2023-536467.8 HIGHdrm/i915/perf: add sentinel to xehp_oa_b_counters
CVE-2022-505287.8 HIGHdrm/amdkfd: Fix memory leakage
CVE-2023-536517.8 HIGHInput: exc3000 - properly stop timer on shutdown
CVE-2022-505437.8 HIGHRDMA/rxe: Fix mr->map double free

Showing top 20 of 118 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53672

No comments yet


Leave a comment