Wind River Support Network

HomeDefectsLIN1022-17940
Fixed

LIN1022-17940 : Security Advisory - linux - CVE-2023-53420

Created: Sep 19, 2025    Updated: Sep 22, 2025
Resolved Date: Sep 22, 2025
Found In Version: 10.22.33.1
Fix Version: 10.22.33.12
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr()  Here is a BUG report from syzbot:  BUG: KASAN: slab-out-of-bounds in ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] BUG: KASAN: slab-out-of-bounds in ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 Read of size 1 at addr ffff888021acaf3d by task syz-executor128/3632  Call Trace:  ntfs_list_ea fs/ntfs3/xattr.c:191 [inline]  ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710  vfs_listxattr fs/xattr.c:457 [inline]  listxattr+0x293/0x2d0 fs/xattr.c:804  Fix the logic of ea_all iteration. When the ea->name_len is 0, return immediately, or Add2Ptr() would visit invalid memory in the next loop.  [almaz.alexandrovich@paragon-software.com: lines of the patch have changed]

CVEs


Live chat
Online