Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53584— ubifs: ubifs_releasepage: Remove ubifs_assert(0) to valid this process

AI Predicted 3.3 Difficulty: Moderate EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d< 7750be5d3e18500b454714677463b500a0b8b0d8affected
1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d< bd188ff1c8a1935c93a1e3cacf3be62667fdf762affected
1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d< 66f4742e93523ab2f062d9d9828b3e590bc61536affected
2.6.27affected
< 2.6.27unaffected
6.1.18≤ 6.1.*unaffected
6.2.5≤ 6.2.*unaffected
6.3≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53584

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ubifs: ubifs_releasepage: Remove ubifs_assert(0) to valid this process
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ubifs: ubifs_releasepage: Remove ubifs_assert(0) to valid this process There are two states for ubifs writing pages: 1. Dirty, Private 2. Not Dirty, Not Private The normal process cannot go to ubifs_releasepage() which means there exists pages being private but not dirty. Reproducer[1] shows that it could occur (which maybe related to [2]) with following process: PA PB PC lock(page)[PA] ubifs_write_end attach_page_private // set Private __set_page_dirty_nobuffers // set Dirty unlock(page) write_cache_pages[PA] lock(page) clear_page_dirty_for_io(page) // clear Dirty ubifs_writepage do_truncation[PB] truncate_setsize i_size_write(inode, newsize) // newsize = 0 i_size = i_size_read(inode) // i_size = 0 end_index = i_size >> PAGE_SHIFT if (page->index > end_index) goto out // jump out: unlock(page) // Private, Not Dirty generic_fadvise[PC] lock(page) invalidate_inode_page try_to_release_page ubifs_releasepage ubifs_assert(c, 0) // bad assertion! unlock(page) truncate_pagecache[PB] Then we may get following assertion failed: UBIFS error (ubi0:0 pid 1683): ubifs_assert_failed [ubifs]: UBIFS assert failed: 0, in fs/ubifs/file.c:1513 UBIFS warning (ubi0:0 pid 1683): ubifs_ro_mode [ubifs]: switched to read-only mode, error -22 CPU: 2 PID: 1683 Comm: aa Not tainted 5.16.0-rc5-00184-g0bca5994cacc-dirty #308 Call Trace: dump_stack+0x13/0x1b ubifs_ro_mode+0x54/0x60 [ubifs] ubifs_assert_failed+0x4b/0x80 [ubifs] ubifs_releasepage+0x67/0x1d0 [ubifs] try_to_release_page+0x57/0xe0 invalidate_inode_page+0xfb/0x130 __invalidate_mapping_pages+0xb9/0x280 invalidate_mapping_pagevec+0x12/0x20 generic_fadvise+0x303/0x3c0 ksys_fadvise64_64+0x4c/0xb0 [1] https://bugzilla.kernel.org/show_bug.cgi?id=215373 [2] https://linux-mtd.infradead.narkive.com/NQoBeT1u/patch-rfc-ubifs-fix-assert-failed-in-ubifs-set-page-dirty
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ubifs_releasepage中移除ubifs_assert(0)验证,可能导致进程状态异常。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d ~ 7750be5d3e18500b454714677463b500a0b8b0d8 -
LinuxLinux 2.6.27 -

II. Public POCs for CVE-2023-53584

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53584

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-10-04 · 144 CVEs total

CVE-2025-399329.8 CRITICALsmb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
CVE-2025-399489.8 CRITICALice: fix Rx page leak on multi-buffer frames
CVE-2025-399469.8 CRITICALtls: make sure to abort the stream if headers are bogus
CVE-2025-399339.4 CRITICALsmb: client: let recv_done verify data_offset, data_length and remaining_data_length
CVE-2025-399439.4 CRITICALksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer
CVE-2025-399528.8 HIGHwifi: wilc1000: avoid buffer overflow in WID string configuration
CVE-2025-399317.8 HIGHcrypto: af_alg - Set merge to zero early in af_alg_sendmsg
CVE-2025-399517.8 HIGHum: virtio_uml: Fix use-after-free after put_device in probe
CVE-2025-399497.8 HIGHqed: Don't collect too many protection override GRC elements
CVE-2025-399457.8 HIGHcnic: Fix use-after-free bugs in cnic_delete_task
CVE-2025-399447.8 HIGHocteontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp()
CVE-2025-399417.8 HIGHzram: fix slot write race condition
CVE-2025-399397.8 HIGHiommu/s390: Fix memory corruption when using identity domain
CVE-2025-399357.8 HIGHASoC: codec: sma1307: Fix memory corruption in sma1307_setting_loaded()
CVE-2025-399427.5 HIGHksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size
CVE-2025-399297.5 HIGHsmb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path
CVE-2022-50503mtd: lpddr2_nvm: Fix possible null-ptr-deref
CVE-2022-50501media: coda: Add check for dcoda_iram_alloc
CVE-2022-50500netdevsim: fix memory leak in nsim_drv_probe() when nsim_dev_resources_register() failed
CVE-2022-50505iommu/amd: Fix pci device refcount leak in ppr_notifier()

Showing top 20 of 144 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53584

No comments yet


Leave a comment