CVE-2023-53526
Description
A flaw was found in the Linux kernel's jbd2 journaling subsystem. A race condition during checkpoint handling could lead to a buffer being incorrectly removed from a transaction's checkpoint list. If a system experiences a crash or power loss before the new transaction is fully committed, this vulnerability can result in corruption of the ext4 filesystem, potentially causing loss of data or metadata.
Statement
The patch fixes a race in jbd2 checkpoint handling where a buffer could be removed from the old checkpoint list after it had already been attached to a new transaction. This could let a checkpoint complete without that buffer and, if a crash/power loss occurs before the new transaction commits, lead to ext4 corruption (lost data/metadata). Severity is Medium due to real integrity and availability impact but high attack complexity (timing-sensitive journal state and often a crash/power interruption).
Mitigation
To mitigate this issue, prevent module jbd2 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.3 | 5.5 | 7.8 |
| Attack Vector | Local | Local | Local |
| Attack Complexity | High | Low | Low |
| Privileges Required | Low | Low | Low |
| User Interaction | None | None | None |
| Scope | Unchanged | Unchanged | Unchanged |
| Confidentiality | None | None | High |
| Integrity Impact | High | None | High |
| Availability Impact | High | High | High |
Vector
Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Other
Technical Impact: Other
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.