Review reviewHigh

CVE-2023-53692

Linux

In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline Syzbot found the following issue: loop0: detected capacity change from 0 to 2048 EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 without journal. Quota mode: none. ================================================================== BUG: KASAN: use-after-free in ext4_ext_binsearch_idx fs/ext4/extents.c:768 [inline] BUG: KASAN: use-after-free in ext4_find_extent+0x76e/0xd90 fs/ext4/extents.c:931 Read of size 4 at addr ffff888073644...

CVSS
7.8
EPSS
0.15%
4.61% percentile
CISA KEV
Not listed
Published
2025.10.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.15%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free read in ext4_find_extent for bigalloc + inline Syzbot found the following issue: loop0: detected capacity change from 0 to 2048 EXT4-fs (loop0): mounted filesystem 00000000-0000-0000-0000-000000000000 without journal. Quota mode: none. ================================================================== BUG: KASAN: use-after-free in ext4_ext_binsearch_idx fs/ext4/extents.c:768 [inline] BUG: KASAN: use-after-free in ext4_find_extent+0x76e/0xd90 fs/ext4/extents.c:931 Read of size 4 at addr ffff888073644...

Affected product and versions

Product
Linux
Affected versions
>= 1ed1eef0551bebee8e56973ccd0900e3578edfb7 < 0ce15000dee0ecd6f235f925a327803e2ef489c6, >= 6f4200ec76a0d31200c308ec5a71c68df5417004 < a34f6dcb78c654ab905642c1b4e7e5fbb4f0babe, >= 9404839e0c9db5a517ea83c0ca3388b39d105fdf < 770b0613637f59f3091dda1ff0c23671a5326b9c, >= d440d6427a5e3a877c1c259b8d2b216ddb65e185 < 40566def189c513be2c694681256d7486cc6e368, >= 81b915181c630ee1cffa052e52874fe4e1ba91ac < 96d440bee177669dc0acedca0abd73bae6a9be8b, >= 131294c35ed6f777bd4e79d42af13b5c41bf2775 < 11c87c8df2cae1d6be83c07e59fef0792de73482, >= 131294c35ed6f777bd4e79d42af13b5c41bf2775 < 14da044725a3ab10affa3566d29c15737c0e67a4, >= 131294c35ed6f777bd4e79d42af13b5c41bf2775 < 835659598c67907b98cd2aa57bb951dfaf675c69, >= c0c8edbc8abbe8f16d80a1d794d1ba2c12b6f193, >= 4.19.270 < 4.19.271, >= 5.4.229 < 5.4.243, >= 5.10.163 < 5.10.180, >= 5.15.87 < 5.15.111, >= 6.1.4 < 6.1.28, >= 6.0.18 < 6.1, >= 6.2
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2023-53692 — Linux | SECUFOCUS NOW