Review reviewHigh

CVE-2023-53862

Linux

In the Linux kernel, the following vulnerability has been resolved: hfs: fix missing hfs_bnode_get() in __hfs_bnode_create Syzbot found a kernel BUG in hfs_bnode_put(): kernel BUG at fs/hfs/bnode.c:466! invalid opcode: 0000 [#1] PREEMPT SMP KASAN CPU: 0 PID: 3634 Comm: kworker/u4:5 Not tainted 6.1.0-rc7-syzkaller-00190-g97ee9d1c1696 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022 Workqueue: writeback wb_workfn (flush-7:0) RIP: 0010:hfs_bnode_put+0x46f/0x480 fs/hfs/bnode.c:466 Code: 8a 80 ff e9 73 fe ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c a0 fe...

CVSS
7.8
EPSS
0.17%
6.30% percentile
CISA KEV
Not listed
Published
2025.12.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.17%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: hfs: fix missing hfs_bnode_get() in __hfs_bnode_create Syzbot found a kernel BUG in hfs_bnode_put(): kernel BUG at fs/hfs/bnode.c:466! invalid opcode: 0000 [#1] PREEMPT SMP KASAN CPU: 0 PID: 3634 Comm: kworker/u4:5 Not tainted 6.1.0-rc7-syzkaller-00190-g97ee9d1c1696 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022 Workqueue: writeback wb_workfn (flush-7:0) RIP: 0010:hfs_bnode_put+0x46f/0x480 fs/hfs/bnode.c:466 Code: 8a 80 ff e9 73 fe ff ff 89 d9 80 e1 07 80 c1 03 38 c1 0f 8c a0 fe...

Affected product and versions

Product
Linux
Affected versions
>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 062af3e9930762d1fd22946748d34e0d859e4a8e, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3a9065a33988c02789722be612f7c42fb8ebbb22, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < eda6879272e4df5456afc36642052ea066f58410, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < dc9f78b6d254427a06e568f2887b1011ef3143ef, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2cab8db14566cf6a516c1f103a60cf6b7f54b1e5, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8140cdc57bc5844cd5e1392673ec2dbf8fdc6940, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 38d72e6604b9f96dffcc0565090cc01622a37b2a, >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a9dc087fd3c484fd1ed18c5efb290efaaf44ce03, >= 2.6.12
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available