In the Linux kernel, the following vulnerability has been resolved:
ext4: remove a BUGON in ext4mbreleasegroup_pa()
If a malicious fuzzer overwrites the ext4 superblock while it is mounted such that the sfirstdatablock is set to a very large number, the calculation of the block group can underflow, and trigger a BUGON check. Change this to be an ext4_warning so that we don't crash the kernel.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53450.json",
"cna_assigner": "Linux"
}[
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-14a8861a",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@185062a21976fbc38f2efd296951b02c4500cf65"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-1dc34d11",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@185062a21976fbc38f2efd296951b02c4500cf65"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-259ea1e5",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@53c14e7cc2257191ba15425c15638fc4f8abb92b"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-2b0c8a3c",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d5bf8f7fb3ee3d99d1303ceb54599ea0599a4a5b"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-499f815c",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@463808f237cf73e98a1a45ff7460c2406a150a0b"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-55208fe8",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d5bf8f7fb3ee3d99d1303ceb54599ea0599a4a5b"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-5ad02208",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@978e5e9111af18741449b81fefd531a622dd969a"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-67b8e216",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef16d8a1798db1a1604ac44ca1bd73ec6bebf483"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-7ca96147",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d87a4e4094c9879fc8acdff8ce59fdffa979c8e0"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-809844c1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0fc279de4bf17e1710bb7e83906538ff8f11111"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-84684f71",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@53c14e7cc2257191ba15425c15638fc4f8abb92b"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-84b0b20b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d87a4e4094c9879fc8acdff8ce59fdffa979c8e0"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-9cca5206",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ef16d8a1798db1a1604ac44ca1bd73ec6bebf483"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-afaed6ec",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bf2a16eb4e6d06124bd8436d4546f61539a65f29"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-bfc153f8",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@463808f237cf73e98a1a45ff7460c2406a150a0b"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-ca8acd67",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0fc279de4bf17e1710bb7e83906538ff8f11111"
},
{
"target": {
"file": "fs/ext4/mballoc.c",
"function": "ext4_mb_release_group_pa"
},
"digest": {
"length": 503.0,
"function_hash": "68558307227737272753781293363744564258"
},
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-dbd8507f",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bf2a16eb4e6d06124bd8436d4546f61539a65f29"
},
{
"target": {
"file": "fs/ext4/mballoc.c"
},
"digest": {
"line_hashes": [
"273351159321437423036228782656981897489",
"201199295377613293462784456152707870865",
"276907830757489784490196927179740009066",
"42345583764536383878023636842641451077"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2023-53450-e3829d66",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@978e5e9111af18741449b81fefd531a622dd969a"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53450.json"