An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udfputsuper and udfcloselvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37454.json"
[
{
"target": {
"file": "include/linux/blkdev.h"
},
"digest": {
"line_hashes": [
"16317466998119689011795586461306084171",
"311258511454331391555162811948352852804",
"109523730787602013648421175098387278768",
"238519977964458717079172925854177814257"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2023-37454-37efbf08",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6f861765464f43a71462d52026fbddfc858239a5",
"deprecated": false,
"signature_version": "v1"
}
]