Junglewise Threat Intelligence

CVE-2023-53537: Linux kernel f2fs use-after-free in IPU bio caching

CVE-2023-53537 · Severity: high · CVSS 7.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's f2fs filesystem implementation caches I/O bio structures for optimization. A bug in error handling could cause the filesystem to incorrectly submit cached I/O operations from unrelated contexts, leading to memory corruption and system crashes. This affects systems using f2fs-formatted storage under error conditions.

Technical details

The vulnerability is a use-after-free bug in the f2fs filesystem driver's bio caching layer, specifically in the f2fs_submit_merged_ipu_write() function. When a checkpoint error (cp_error) is triggered, the function attempts to flush cached In-Place Update (IPU) bio structures without validating whether the bio pointer is valid, resulting in submission of random cached bios from other I/O contexts. This occurs in the write path during page writeback (f2fs_write_single_data_page). The attack vector is local and requires the ability to trigger filesystem errors, typically through crafted I/O operations or storage errors. An attacker can cause kernel crashes (denial of service) or potentially memory corruption. The fix adds validation checks before submitting cached bios, ensuring only valid bios are submitted.

Affected products

  • Linux Linux Kernel Affected versions include f2fs implementations from kernel 5.0 through at least 6.2; patched in stable releases via commit 5cdb422c839134273866208dad5360835ddb9794

Timeline

  • 2023-04-10: disclosed
  • 2023-04-10: patched: Patch committed upstream; backported to stable series by May 2023

References

Related threats