Answer in brief
CVE-2023-53420 records a Unknown severity vulnerability in ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.15 | Not reported |
| Linux/Linuxgeneric | >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <f3380d895e28a32632eb3609f5bd515adee4e5a1 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <c86a2517df6c9304db8fb12b77136ec7a5d85994 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <721b75ea2dfce53a8890dff92ae01afca8e74f88 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <3c675ddffb17a8b1e32efad5c983254af18b12c2 | f3380d895e28a32632eb3609f5bd515adee4e5a1, c86a2517df6c9304db8fb12b77136ec7a5d85994, 721b75ea2dfce53a8890dff92ae01afca8e74f88, 3c675ddffb17a8b1e32efad5c983254af18b12c2 |
Published upstream
Sep 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BUG report from syzbot: BUG: KASAN: slab-out-of-bounds in ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] BUG: KASAN: slab-out-of-bounds in ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 Read of size 1 at addr ffff888021acaf3d by task syz-executor128/3632 Call Trace: ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 vfs_listxattr fs/xattr.c:457 [inline] listxattr+0x293/0x2d0 fs/xattr.c:804 Fix the logic of ea_all iteration. When the ea->name_len is 0, return immediately, or Add2Ptr() would visit invalid memory in the next loop. [[email protected]: lines of the patch have changed]
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53420 records a Unknown severity vulnerability in ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 5.15 | Not reported |
| Linux/Linuxgeneric | >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <f3380d895e28a32632eb3609f5bd515adee4e5a1 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <c86a2517df6c9304db8fb12b77136ec7a5d85994 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <721b75ea2dfce53a8890dff92ae01afca8e74f88 || >=be71b5cba2e6485e8959da7a9f9a44461a1bb074 <3c675ddffb17a8b1e32efad5c983254af18b12c2 | f3380d895e28a32632eb3609f5bd515adee4e5a1, c86a2517df6c9304db8fb12b77136ec7a5d85994, 721b75ea2dfce53a8890dff92ae01afca8e74f88, 3c675ddffb17a8b1e32efad5c983254af18b12c2 |
Published upstream
Sep 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix panic about slab-out-of-bounds caused by ntfs_listxattr() Here is a BUG report from syzbot: BUG: KASAN: slab-out-of-bounds in ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] BUG: KASAN: slab-out-of-bounds in ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 Read of size 1 at addr ffff888021acaf3d by task syz-executor128/3632 Call Trace: ntfs_list_ea fs/ntfs3/xattr.c:191 [inline] ntfs_listxattr+0x401/0x570 fs/ntfs3/xattr.c:710 vfs_listxattr fs/xattr.c:457 [inline] listxattr+0x293/0x2d0 fs/xattr.c:804 Fix the logic of ea_all iteration. When the ea->name_len is 0, return immediately, or Add2Ptr() would visit invalid memory in the next loop. [[email protected]: lines of the patch have changed]
Quoted source text, attributed separately from HOL analysis.