{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-53526",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-10-01T11:39:39.407Z",
        "datePublished": "2025-10-01T11:46:11.862Z",
        "dateUpdated": "2026-08-05T09:14:37.200Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:14:37.200Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check 'jh->b_transaction' before removing it from checkpoint\n\nFollowing process will corrupt ext4 image:\nStep 1:\njbd2_journal_commit_transaction\n __jbd2_journal_insert_checkpoint(jh, commit_transaction)\n // Put jh into trans1->t_checkpoint_list\n journal->j_checkpoint_transactions = commit_transaction\n // Put trans1 into journal->j_checkpoint_transactions\n\nStep 2:\ndo_get_write_access\n test_clear_buffer_dirty(bh) // clear buffer dirty，set jbd dirty\n __jbd2_journal_file_buffer(jh, transaction) // jh belongs to trans2\n\nStep 3:\ndrop_cache\n journal_shrink_one_cp_list\n  jbd2_journal_try_remove_checkpoint\n   if (!trylock_buffer(bh))  // lock bh, true\n   if (buffer_dirty(bh))     // buffer is not dirty\n   __jbd2_journal_remove_checkpoint(jh)\n   // remove jh from trans1->t_checkpoint_list\n\nStep 4:\njbd2_log_do_checkpoint\n trans1 = journal->j_checkpoint_transactions\n // jh is not in trans1->t_checkpoint_list\n jbd2_cleanup_journal_tail(journal)  // trans1 is done\n\nStep 5: Power cut, trans2 is not committed, jh is lost in next mounting.\n\nFix it by checking 'jh->b_transaction' before remove it from checkpoint."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable checkpoint scan is reached through ordinary VFS write/fsync syscalls and memory reclaim on a locally mounted ext4/ocfs2 filesystem. There is no network protocol handler involved, so the attacker needs local access (or an account on a shared host).\nAC:L - The attacker drives both sides of the race entirely from userspace — repeatedly re-dirtying already-checkpointed metadata blocks (rename/unlink/create storms against the same inode-table and bitmap blocks) while allocating memory to fire the jbd2 shrinker, on top of the commit-time `__jbd2_journal_clean_checkpoint_list()` path that runs every 5 seconds regardless. The window can be retried indefinitely at no cost, and the unclean shutdown that exposes the loss is routine in the deployment classes most affected (embedded, automotive, IoT, battery devices, cloud instances subject to host failure).\nPR:L - Any unprivileged local user with write access to any ext4/ocfs2 filesystem — /tmp or their own home directory suffices — generates the journal commits and reclaim pressure that hit the racy path. No capabilities, mount privileges, or user-namespace tricks are needed.\nUI:N - The attacker's own filesystem workload plus background commit/reclaim activity is sufficient; no action by any other user is required. The subsequent power loss or crash is an environmental event, not user interaction.\nS:U - The corruption stays within the kernel's own filesystem stack and the affected block device; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Rolling a metadata block back to a pre-trans1 state resurrects stale inode block pointers and allocation bitmaps, cross-linking blocks that were freed and have since been reallocated to other users' files, so an unprivileged user can end up reading arbitrary other-tenant file contents. The exposure is unbounded in size rather than a small fixed leak.\nI:H - The bug causes silent, permanent loss of committed filesystem metadata — inode tables, block/inode bitmaps, extent trees and directory blocks (and file data under data=journal) — that survives journal replay, which is exactly the \"corrupt ext4 image\" outcome described by the fix author. This is arbitrary, attacker-influenced modification of on-disk state with no integrity protection remaining.\nA:H - The resulting inconsistency triggers `ext4_error()` on the next access, which takes the filesystem read-only under the default errors=remount-ro or panics the machine under errors=panic; a corrupted root filesystem leaves an embedded, automotive, or appliance device unbootable until an offline fsck."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/jbd2/checkpoint.c"
                    ],
                    "versions": [
                        {
                            "version": "b832174b7f89df3ebab02f5b485d00127a0e1a6e",
                            "lessThan": "ef5fea70e5915afd64182d155e72bfb4f275e1fc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e5c768d809a85e9efd0274b2efe69d4970cc0014",
                            "lessThan": "dbafe636db415299e54d9dfefc1003bda9e71c9d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "46f881b5b1758dc4a35fba4a643c10717d0cf427",
                            "lessThan": "2298f2589903a8bc03061b54b31fd97985ab6529",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "46f881b5b1758dc4a35fba4a643c10717d0cf427",
                            "lessThan": "590a809ff743e7bd890ba5fb36bc38e20a36de53",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "019b59aeb2af6b47d5c8e69c5dc1d731c8df0354",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.15.129",
                            "lessThan": "5.15.132",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.50",
                            "lessThan": "6.1.54",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.4.13",
                            "lessThan": "6.5",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/jbd2/checkpoint.c"
                    ],
                    "versions": [
                        {
                            "version": "6.5",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.5",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.132",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.54",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.5.4",
                            "lessThanOrEqual": "6.5.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.129",
                                    "versionEndExcluding": "5.15.132"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.50",
                                    "versionEndExcluding": "6.1.54"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.5",
                                    "versionEndExcluding": "6.5.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.5",
                                    "versionEndExcluding": "6.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.4.13"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/ef5fea70e5915afd64182d155e72bfb4f275e1fc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/dbafe636db415299e54d9dfefc1003bda9e71c9d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/2298f2589903a8bc03061b54b31fd97985ab6529"
                },
                {
                    "url": "https://git.kernel.org/stable/c/590a809ff743e7bd890ba5fb36bc38e20a36de53"
                }
            ],
            "title": "jbd2: check 'jh->b_transaction' before removing it from checkpoint",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}