erofs: stop parsing non-compact HEAD index if clusterofs is invalid
Summary
| CVE | CVE-2023-54132 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-24 13:16:15 UTC |
| Updated | 2026-08-04 10:19:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: erofs: stop parsing non-compact HEAD index if clusterofs is invalid Syzbot generated a crafted image [1] with a non-compact HEAD index of clusterofs 33024 while valid numbers should be 0 ~ lclustersize-1, which causes the following unexpected behavior as below: BUG: unable to handle page fault for address: fffff52101a3fff9 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 23ffed067 P4D 23ffed067 PUD 0 Oops: 0000 [#1] PREEMPT SMP KASAN CPU: 1 PID: 4398 Comm: kworker/u5:1 Not tainted 6.3.0-rc6-syzkaller-g09a9639e56c0 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023 Workqueue: erofs_worker z_erofs_decompressqueue_work RIP: 0010:z_erofs_decompress_queue+0xb7e/0x2b40 ... Call Trace: <TASK> z_erofs_decompressqueue_work+0x99/0xe0 process_one_work+0x8f6/0x1170 worker_thread+0xa63/0x1210 kthread+0x270/0x300 ret_from_fork+0x1f/0x30 Note that normal images or images using compact indexes are not impacted. Let's fix this now. [1] https://lore.kernel.org/r/[email protected] |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001500000 probability, percentile 0.047060000 (date 2026-08-06)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d 880c79bdb002b9d5b6940e52c2ad3829c2178207 git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d 7a4579cd6e4936de107c82499c3c9ee11b63401e git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d 060fecf1114ff9fcfe87953fe8c4fc5048777160 git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d 7ee7a86e28ce9ead7112286c388df8d254c373c6 git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d f01b2894928affa3339d355608713cf3db8360b8 git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d 96a845419b3722869f09883319de4d55c44d9aef git | Not specified |
| CNA | Linux | Linux | affected 02827e1796b33f1794966f5c3101f8da2dfa9c1d cc4efd3dd2ac9f89143e5d881609747ecff04164 git | Not specified |
| CNA | Linux | Linux | affected 4.19 | Not specified |
| CNA | Linux | Linux | unaffected 4.19 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.243 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.180 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.111 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.28 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.2.15 6.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.3.2 6.3.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/7a4579cd6e4936de107c82499c3c9ee11b63401e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/cc4efd3dd2ac9f89143e5d881609747ecff04164 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/060fecf1114ff9fcfe87953fe8c4fc5048777160 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f01b2894928affa3339d355608713cf3db8360b8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7ee7a86e28ce9ead7112286c388df8d254c373c6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/96a845419b3722869f09883319de4d55c44d9aef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/880c79bdb002b9d5b6940e52c2ad3829c2178207 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.