udf: Detect system inodes linked into directory hierarchy
Summary
| CVE | CVE-2023-53695 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-22 14:15:44 UTC |
| Updated | 2026-08-04 10:19:18 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: udf: Detect system inodes linked into directory hierarchy When UDF filesystem is corrupted, hidden system inodes can be linked into directory hierarchy which is an avenue for further serious corruption of the filesystem and kernel confusion as noticed by syzbot fuzzed images. Refuse to access system inodes linked into directory hierarchy and vice versa. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001550000 probability, percentile 0.051360000 (date 2026-08-05)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f 1dc71eeb198a8daa17d0c995998a53b0b749a158 git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f d747b31e2925a2f384e7dd1901a2e5bc5f984ed8 git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f a44ec34b90440ada190924f5908b97026504fdcd git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f 37e74003d81e79457535cbbdfa1603431c03fac0 git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f 1f328751b65c49c13a312d67a3bf27766b85baf7 git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f 9e3b5ef7d02eaa6553e79b4af9bd99227280f245 git | Not specified |
| CNA | Linux | Linux | affected 6174c2eb8ecef271159bdcde460ce8af54d8f72f 85a37983ec69cc9fcd188bc37c4de15ee326355a git | Not specified |
| CNA | Linux | Linux | affected 801c7a20d255e300ab51a6fcb1d0e218d136b16f git | Not specified |
| CNA | Linux | Linux | affected 3.17.2 3.18 semver | Not specified |
| CNA | Linux | Linux | affected 3.18 | Not specified |
| CNA | Linux | Linux | unaffected 3.18 semver | Not specified |
| CNA | Linux | Linux | unaffected 4.19.278 4.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.235 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.173 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.99 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.16 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.2.3 6.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/9e3b5ef7d02eaa6553e79b4af9bd99227280f245 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/85a37983ec69cc9fcd188bc37c4de15ee326355a | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/37e74003d81e79457535cbbdfa1603431c03fac0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d747b31e2925a2f384e7dd1901a2e5bc5f984ed8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1f328751b65c49c13a312d67a3bf27766b85baf7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a44ec34b90440ada190924f5908b97026504fdcd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1dc71eeb198a8daa17d0c995998a53b0b749a158 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.