Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv9v-wv5c-gp87

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью

Описание

In the Linux kernel, the following vulnerability has been resolved:

ext4: Fix possible corruption when moving a directory

When we are renaming a directory to a different directory, we need to update '..' entry in the moved directory. However nothing prevents moved directory from being modified and even converted from the inline format to the normal format. When such race happens the rename code gets confused and we crash. Fix the problem by locking the moved directory.

In the Linux kernel, the following vulnerability has been resolved:

ext4: Fix possible corruption when moving a directory

When we are renaming a directory to a different directory, we need to update '..' entry in the moved directory. However nothing prevents moved directory from being modified and even converted from the inline format to the normal format. When such race happens the rename code gets confused and we crash. Fix the problem by locking the moved directory.

Связанные уязвимости

ubuntu
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS3: 3.6
redhat
больше 1 года назад

This CVE-2023-53137 has been officially rejected upstream because the original ext4-level fix it referred to (8dac5a63cf79707b...) was later reverted in Linux v6.5 (3658840cd363 ext4: Remove ext4 locking of moved directory). The upstream maintainers determined that the problem was more appropriately addressed at the VFS (Virtual Filesystem) layer, rather than within the ext4 filesystem itself. A new set of commits, starting with 28eceeda130f (fs: Lock moved directories) and followed by several refinements (66d8fc0539b0, 22e111ed6c83), implemented proper directory move locking across all filesystems. These commits are present in all maintained stable and LTS kernels, effectively rendering the ext4-specific fix obsolete. However, in older kernel branches (around v6.3–v6.4) that contain only the ext4-level patch and not the VFS-level locking changes, a narrow race condition could still theoretically occur when renaming directories, potentially leading to metadata corruption. Because ...

nvd
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

suse-cvrf
около 1 года назад

Security update for the Linux Kernel

suse-cvrf
около 1 года назад

Security update for the Linux Kernel