CVE-2023-53763 addresses an array-index-out-of-bounds vulnerability within the F2FS filesystem driver in the Linux kernel. This flaw, discovered by syzbot, arises from an incorrect application of patches intended to fix an extent cache sanity check. Specifically, both an initial and a subsequent fix were applied, leading to the reported issue. The vulnerability has a FAUCET Risk Score of 7/100 and an EPSS score indicating low exploitability. While a CVSS score is not provided, the nature of an out-of-bounds error in a filesystem driver suggests potential for system instability, denial of service, or possibly privilege escalation if an attacker can control the index. The attack vector would likely involve mounting a specially crafted F2FS filesystem. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low public attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.29, < 6.1.53CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2.5, < 6.3CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.