Junglewise Threat Intelligence

CVE-2023-53763: Linux kernel f2fs array index out of bounds in extent cache

CVE-2023-53763 · Severity: high · CVSS 7.8 · Published 2025-12-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

F2FS is a flash-friendly filesystem used in Linux kernel to optimize performance on solid-state storage. A bug in the extent cache validation logic causes an array index to exceed bounds during inode recovery, potentially leading to memory corruption or denial of service when mounting a maliciously crafted f2fs filesystem.

Technical details

The vulnerability is an array-index-out-of-bounds error in fs/f2fs/f2fs.h:3275 within the inline_data_addr() function, triggered during inode recovery (__recover_inline_status in inode.c:113). The root cause stems from an incomplete or incorrect extent cache sanity check that fails to properly validate array bounds before accessing the __le32[923] array. The bug occurs during filesystem mount when f2fs_iget() calls do_read_inode(), requiring a maliciously crafted f2fs filesystem image to trigger. An attacker with the ability to provide a crafted filesystem image can trigger out-of-bounds memory access, leading to information disclosure, denial of service, or potential code execution. The fix requires reverting commit d48a7b3a72f1 and keeping only the v2 patch (commit 269d11948100) which properly addresses the sanity check.

Affected products

  • Linux Linux kernel affected versions include Linux 6.0 and later (introduced in commit d48a7b3a72f1 from January 2023, fixed by reverting that commit and retaining commit 269d11948100 from February 2023)

Timeline

  • 2025-12-08: disclosed: CVE-2023-53763 published
  • 2023-01: other: Vulnerable commit d48a7b3a72f1 introduced
  • 2023-02: patched: Correct fix applied via commit 269d11948100 (v2 patch); vulnerable v1 patch needs reversion

Related threats