CVE-2023-53337 Details
Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: do not write dirty data after degenerating to read-only According to syzbot's report, mark_buffer_dirty() called from nilfs_segctor_do_construct() outputs a warning with some patterns after nilfs2 detects metadata corruption and degrades to read-only mode. After such read-only degeneration, page cache data may be cleared through nilfs_clear_dirty_page() which may also clear the uptodate flag for their buffer heads. However, even after the degeneration, log writes are still performed by unmount processing etc., which causes mark_buffer_dirty() to be called for buffer heads without the "uptodate" flag and causes the warning. Since any writes should not be done to a read-only file system in the first place, this fixes the warning in mark_buffer_dirty() by letting nilfs_segctor_do_construct() abort early if in read-only mode. This also changes the retry check of nilfs_segctor_write_out() to avoid unnecessary log write retries if it detects -EROFS that nilfs_segctor_do_construct() returned.
A vulnerability in the Linux kernel's nilfs2 filesystem has been addressed. The issue arose when nilfs2 detected metadata corruption, leading to a degradation to read-only mode. Despite this, log writes were still performed, causing a warning to be issued. The vulnerability occurred because the system attempted to write dirty data to a read-only filesystem, which is not permissible. The issue has been resolved by modifying the behavior of certain functions to respect the read-only status and prevent unnecessary write retries during unmount processing.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/13f73ef77baa4764dc1ca4fcbae9cade05b83866 | kernel.org | Patch |
| https://git.kernel.org/stable/c/28a65b49eb53e172d23567005465019658bfdb4d | kernel.org | Patch |
| https://git.kernel.org/stable/c/4005cec6847c06ee191583270b7cdd7e696543cc | kernel.org | Patch |
| https://git.kernel.org/stable/c/4569a292a84e340e97d178898ad1cfe1a3080a61 | kernel.org | Patch |
| https://git.kernel.org/stable/c/55f7810632f993cff622a0ddbc7c865892294b61 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7c3e662048053802f6b0db3a78e97f4e1f7edc4f | kernel.org | Patch |
| https://git.kernel.org/stable/c/a73201c607d8e506358d60aafddda4246bdd9350 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bd89073fc7a5d03b1d06b372addbe405e5a925f4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e9c5412c5972124776c1b873533eb39e287a4dfa | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.14.315 >= 4.15, < 4.19.283 >= 4.20, < 5.4.243 >= 5.5, < 5.10.180 >= 5.11, < 5.15.111 >= 5.16, < 6.1.28 >= 6.2, < 6.2.15 >= 6.3, < 6.3.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | CVE Modified | CISA-ADP |
| Dec 11, 2025 | Initial Analysis | [email protected] |
| Sep 17, 2025 | New CVE Received | kernel.org |