DEBIAN-CVE-2023-53835

    Dashboard / Vulnerabilities / DEBIAN-CVE-2023-53835

    DEBIAN-CVE-2023-53835

    Published: 1 Jan 1Last Modified: 9 Dec 2025
    Upstream:

    Summary:

    Details: In the Linux kernel, the following vulnerability has been resolved: ext4: don't clear SB_RDONLY when remounting r/w until quota is re-enabled When a file system currently mounted read/only is remounted read/write, if we clear the SB_RDONLY flag too early, before the quota is initialized, and there is another process/thread constantly attempting to create a directory, it's possible to trigger the WARN_ON_ONCE(dquot_initialize_needed(inode)); in ext4_xattr_block_set(), with the following stack trace: WARNING: CPU: 0 PID: 5338 at fs/ext4/xattr.c:2141 ext4_xattr_block_set+0x2ef2/0x3680 RIP: 0010:ext4_xattr_block_set+0x2ef2/0x3680 fs/ext4/xattr.c:2141 Call Trace: ext4_xattr_set_handle+0xcd4/0x15c0 fs/ext4/xattr.c:2458 ext4_initxattrs+0xa3/0x110 fs/ext4/xattr_security.c:44 security_inode_init_security+0x2df/0x3f0 security/security.c:1147 __ext4_new_inode+0x347e/0x43d0 fs/ext4/ialloc.c:1324 ext4_mkdir+0x425/0xce0 fs/ext4/namei.c:2992 vfs_mkdir+0x29d/0x450 fs/namei.c:4038 do_mkdirat+0x264/0x520 fs/namei.c:4061 __do_sys_mkdirat fs/namei.c:4076 [inline] __se_sys_mkdirat fs/namei.c:4074 [inline] __x64_sys_mkdirat+0x89/0xa0 fs/namei.c:4074

    Affected packages

    Package

    Name: linux

    Purl: pkg:deb/debian/linux?arch=source

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.10.191-1

    Affected versions

    5.10.103-1
    5.10.103-1~bpo10+1
    5.10.106-1
    5.10.113-1
    5.10.120-1
    5.10.120-1~bpo10+1
    5.10.127-1
    5.10.127-2
    5.10.127-2~bpo10+1
    5.10.136-1
    5.10.140-1
    5.10.148-1
    5.10.149-1
    5.10.149-2
    5.10.158-1
    5.10.158-2
    5.10.162-1
    5.10.178-1
    5.10.178-2
    5.10.178-3
    5.10.179-1
    5.10.179-2
    5.10.179-3
    5.10.179-4
    5.10.179-5
    5.10.46-4
    5.10.46-5
    5.10.70-1
    5.10.70-1~bpo10+1
    5.10.84-1
    5.10.92-1
    5.10.92-1~bpo10+1
    5.10.92-2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High