Junglewise Threat Intelligence

CVE-2023-53626: Linux kernel ext4 double unlock in directory rename

CVE-2023-53626 · Severity: high · CVSS 7.8 · Published 2025-10-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's ext4 filesystem can cause a double unlock of a directory inode when moving or renaming a directory. This can lead to kernel lock corruption, causing system crashes, data corruption, or a denial of service on systems using ext4-based storage.

Technical details

The vulnerability is a double-unlock bug in the ext4_rename function in fs/ext4/namei.c. When renaming a directory, if ext4_rename_dir_prepare() fails, the code path incorrectly calls inode_unlock() on the old directory inode before jumping to end_rename, where the inode is unlocked a second time. This is a concurrency/locking error that can corrupt kernel synchronization primitives. The bug affects the kernel's directory rename operation, which is accessible locally to any process performing filesystem operations. A fix removes the redundant inode_unlock() call on the error path. Patches are available in the Linux stable kernel tree.

Affected products

  • Linux Linux kernel multiple versions with ext4 filesystem support

Timeline

  • 2023-03-17: disclosed
  • 2023-03-22: patched

References

Related threats