{"schema_version":"1.9.0","id":"CVE-2023-53683","published":"2025-10-07T15:21:36.715Z","modified":"2026-08-12T03:51:48.040706516Z","related":["SUSE-SU-2025:4111-1","SUSE-SU-2025:4139-1","SUSE-SU-2025:4149-1","SUSE-SU-2025:4189-1","SUSE-SU-2025:4320-1"],"summary":"fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()\n\nsyzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for\ncrafted filesystem image can contain bogus length. There conditions are\nnot kernel bugs that can justify kernel to panic.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f62f5ee63052324ad94dd05091743d9e09f72070"},{"fixed":"61af77acd039ffd221bf7adf0dc95d0a4d377505"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ab778439c6fa0071698b62a351f79d319fd72c53"},{"fixed":"c074913b12db3632b11588b31bbfb0fa80a0a1c9"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"781fa141414ef18b52f15037497155f80bf0ecab"},{"fixed":"a75d9211a07fed513c08c5d4861c4a36ac6a74fe"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"1f881d9201f6e0a917004a14329f9ff3d0bfa1e5"},{"fixed":"c8daee66585897a4c90d937c91e762100237bff9"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"48d9e2e6de01ed35e965eb549758a837c07b601d"},{"fixed":"37cab61a52d6f42b2d961c51bcf369f09e235fb5"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"55d1cbbbb29e6656c662ee8f73ba1fc4777532eb"},{"fixed":"48960a503fcec76d3f72347b7e679dda08ca43be"},{"fixed":"3a9d68d84b2e41ba3f2a727b36f035fad6800492"},{"fixed":"81b21c0f0138ff5a499eafc3eb0578ad2a99622c"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.14.303"},{"fixed":"4.14.316"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.19.270"},{"fixed":"4.19.284"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.4.229"},{"fixed":"5.4.244"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.10.163"},{"fixed":"5.10.181"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.15.87"},{"fixed":"5.15.113"}]}],"versions":["v4.14.315","v4.14.314","v4.14.313","v4.14.312","v4.14.311","v4.14.310","v4.14.309","v4.14.308","v4.14.307","v4.14.306","v4.14.305","v4.14.304","v4.14.303","v4.19.283","v4.19.282","v4.19.281","v4.19.280","v4.19.279","v4.19.278","v4.19.277","v4.19.276","v4.19.275","v4.19.274","v4.19.273","v4.19.272","v4.19.271","v4.19.270","v5.4.243","v5.4.242","v5.4.241","v5.4.240","v5.4.239","v5.4.238","v5.4.237","v5.4.236","v5.4.235","v5.4.234","v5.4.233","v5.4.232","v5.4.231","v5.4.230","v5.4.229","v5.10.180","v5.10.179","v5.10.178","v5.10.177","v5.10.176","v5.10.175","v5.10.174","v5.10.173","v5.10.172","v5.10.171","v5.10.170","v5.10.169","v5.10.168","v5.10.167","v5.10.166","v5.10.165","v5.10.164","v5.10.163","v5.15.112","v5.15.111","v5.15.110","v5.15.109","v5.15.108","v5.15.107","v5.15.106","v5.15.105","v5.15.104","v5.15.103","v5.15.102","v5.15.101","v5.15.100","v5.15.99","v5.15.98","v5.15.97","v5.15.96","v5.15.95","v5.15.94","v5.15.93","v5.15.92","v5.15.91","v5.15.90","v5.15.89","v5.15.88","v5.15.87"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53683.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.14.316"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.19.284"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.244"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.181"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.113"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.30"},{"fixed":"6.3.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53683.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/37cab61a52d6f42b2d961c51bcf369f09e235fb5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3a9d68d84b2e41ba3f2a727b36f035fad6800492"},{"type":"WEB","url":"https://git.kernel.org/stable/c/48960a503fcec76d3f72347b7e679dda08ca43be"},{"type":"WEB","url":"https://git.kernel.org/stable/c/61af77acd039ffd221bf7adf0dc95d0a4d377505"},{"type":"WEB","url":"https://git.kernel.org/stable/c/81b21c0f0138ff5a499eafc3eb0578ad2a99622c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a75d9211a07fed513c08c5d4861c4a36ac6a74fe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c074913b12db3632b11588b31bbfb0fa80a0a1c9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c8daee66585897a4c90d937c91e762100237bff9"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53683.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53683"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53683.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}