CVE-2023-53732
Last modified
CVE-2023-53732 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL dereference in ni_write_inode Syzbot reports a NULL dereference in ni_write_inode. When creating a new inode, if allocation fails in mi_init function (called in mi_format_new function), mi->mrec is set to NULL. In the error path of this inode creation, mi->mrec is later dereferenced in ni_write_inode. Add a NULL check to prevent NULL dereference.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix NULL dereference in ni_write_inode Syzbot reports a NULL dereference in ni_write_inode. When creating a new inode, if allocation fails in mi_init function (called in mi_format_new function), mi->mrec is set to NULL. In the error path of this inode creation, mi->mrec is later dereferenced in ni_write_inode. Add a NULL check to prevent NULL dereference.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e, < d4b74482529516477cf7b12502538e51827c699f; >= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e, < b3152afc0eb864f7c6ecad134a15b577ef7aec77; >= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e, < b1135fbaf8ebef93df326761ac70ebcc3c2e3d63; >= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e, < 8dae4f6341e335a09575be60b4fdf697c732a470 |
| Linux | Linux | 5.15 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-53732?
How severe is CVE-2023-53732?
How do I fix CVE-2023-53732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-53727In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53728In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53729In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-5373A vulnerability classified as critical has been found in Sou…9.8
- CVE-2023-53730In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53731In the Linux kernel, the following vulnerability has been re…
- CVE-2023-53733In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-53734dawa-pharma-1.0 allows unauthenticated attackers to execute …8.7
- CVE-2023-53735WEBIGniter 28.7.23 contains a cross-site scripting vulnerabi…5.3
- CVE-2023-53736A reflected cross-site scripting vulnerability in Kentico Xp…5.4
- CVE-2023-53737A stored cross-site scripting vulnerability in Kentico Xperi…4.8
- CVE-2023-53738A reflected cross-site scripting vulnerability in Kentico Xp…5.4
Are you affected by CVE-2023-53732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
