Junglewise Threat Intelligence

CVE-2023-54132: Linux kernel erofs heap overflow via invalid HEAD index

CVE-2023-54132 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The erofs filesystem driver in the Linux kernel failed to validate a critical index value when parsing compressed filesystem images, allowing a maliciously crafted image to trigger an out-of-bounds memory access. An attacker who can mount a crafted erofs image—either locally or through a compromised storage source—can crash the system or potentially execute code in kernel context.

Technical details

The vulnerability is an input validation failure in the erofs filesystem driver (fs/erofs/zmap.c) in the legacy_load_cluster_from_disk() function. When parsing non-compact HEAD index entries, the code reads a clusterofs value from disk and uses it without validating that it falls within the valid range (0 to lclustersize-1). A syzbot-generated crafted image with a clusterofs of 33024 caused out-of-bounds memory access during decompression, triggering a page fault in z_erofs_decompress_queue(). The attack requires the ability to mount a malicious erofs image, which can be achieved locally or via network-accessible storage. The fix adds a bounds check that returns -EFSCORRUPTED if clusterofs exceeds the maximum valid value. Patches have been merged into mainline and stable kernel branches as of May 2023.

Affected products

  • Linux Linux kernel Linux 4.18 through 6.3 (affected versions vary by stable branch)

Timeline

  • 2023-04-11: disclosed: Vulnerability discovered by syzbot and reported to kernel developers
  • 2023-05-11: patched: Fix merged into stable kernels via commit 060fecf1114ff9fcfe87953fe8c4fc5048777160
  • 2025-12-24: advisory: CVE-2023-54132 disclosed to NVD

References

Related threats