CVE-2023-54132
In the Linux kernel, the following vulnerability has been resolved:
erofs: stop parsing non-compact HEAD index if clusterofs is invalid
Syzbot generated a crafted image [1] with a non-compact HEAD index of clusterofs 33024 while valid numbers should be 0 ~ lclustersize-1, which causes the following unexpected behavior as below:
Note that normal images or images using compact indexes are not impacted. Let's fix this now.
[1] https://lore.kernel.org/r/000000000000ec75b005ee97fbaa@google.com
Detalles técnicos trazas, registros y código del informe original
BUG: unable to handle page fault for address: fffff52101a3fff9 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 23ffed067 P4D 23ffed067 PUD 0 Oops: 0000 [#1] PREEMPT SMP KASAN CPU: 1 PID: 4398 Comm: kworker/u5:1 Not tainted 6.3.0-rc6-syzkaller-g09a9639e56c0 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023 Workqueue: erofs_worker z_erofs_decompressqueue_work RIP: 0010:z_erofs_decompress_queue+0xb7e/0x2b40 ... Call Trace: <TASK> z_erofs_decompressqueue_work+0x99/0xe0 process_one_work+0x8f6/0x1170 worker_thread+0xa63/0x1210 kthread+0x270/0x300 ret_from_fork+0x1f/0x30
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution75 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation60 %
Requiere interacción del usuario (UI:R) para abrir una imagen EROFS manipulada; causa DoS por page fault o escalada si el kernel ejecuta código adicional ante corrupción de memoria.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/060fecf1114ff9fcfe87953fe8c4fc5048777160
- https://git.kernel.org/stable/c/7a4579cd6e4936de107c82499c3c9ee11b63401e
- https://git.kernel.org/stable/c/7ee7a86e28ce9ead7112286c388df8d254c373c6
- https://git.kernel.org/stable/c/880c79bdb002b9d5b6940e52c2ad3829c2178207
- https://git.kernel.org/stable/c/96a845419b3722869f09883319de4d55c44d9aef
- https://git.kernel.org/stable/c/cc4efd3dd2ac9f89143e5d881609747ecff04164
- https://git.kernel.org/stable/c/f01b2894928affa3339d355608713cf3db8360b8
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-54132",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "880c79bdb002b9d5b6940e52c2ad3829c2178207",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "7a4579cd6e4936de107c82499c3c9ee11b63401e",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "060fecf1114ff9fcfe87953fe8c4fc5048777160",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "7ee7a86e28ce9ead7112286c388df8d254c373c6",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "f01b2894928affa3339d355608713cf3db8360b8",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "96a845419b3722869f09883319de4d55c44d9aef",
"versionType": "git"
},
{
"status": "affected",
"version": "02827e1796b33f1794966f5c3101f8da2dfa9c1d",
"lessThan": "cc4efd3dd2ac9f89143e5d881609747ecff04164",
"versionType": "git"
}
],
"programFiles": [
"fs/erofs/zmap.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.4.243",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.180",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.111",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.28",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.2.15",
"versionType": "semver",
"lessThanOrEqual": "6.2.*"
},
{
"status": "unaffected",
"version": "6.3.2",
"versionType": "semver",
"lessThanOrEqual": "6.3.*"
},
{
"status": "unaffected",
"version": "6.4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/erofs/zmap.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-24T13:16:15.180",
"references": [
{
"url": "https://git.kernel.org/stable/c/060fecf1114ff9fcfe87953fe8c4fc5048777160",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7a4579cd6e4936de107c82499c3c9ee11b63401e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7ee7a86e28ce9ead7112286c388df8d254c373c6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/880c79bdb002b9d5b6940e52c2ad3829c2178207",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/96a845419b3722869f09883319de4d55c44d9aef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc4efd3dd2ac9f89143e5d881609747ecff04164",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f01b2894928affa3339d355608713cf3db8360b8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: stop parsing non-compact HEAD index if clusterofs is invalid\n\nSyzbot generated a crafted image [1] with a non-compact HEAD index of\nclusterofs 33024 while valid numbers should be 0 ~ lclustersize-1,\nwhich causes the following unexpected behavior as below:\n\n BUG: unable to handle page fault for address: fffff52101a3fff9\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 23ffed067 P4D 23ffed067 PUD 0\n Oops: 0000 [#1] PREEMPT SMP KASAN\n CPU: 1 PID: 4398 Comm: kworker/u5:1 Not tainted 6.3.0-rc6-syzkaller-g09a9639e56c0 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/30/2023\n Workqueue: erofs_worker z_erofs_decompressqueue_work\n RIP: 0010:z_erofs_decompress_queue+0xb7e/0x2b40\n ...\n Call Trace:\n <TASK>\n z_erofs_decompressqueue_work+0x99/0xe0\n process_one_work+0x8f6/0x1170\n worker_thread+0xa63/0x1210\n kthread+0x270/0x300\n ret_from_fork+0x1f/0x30\n\nNote that normal images or images using compact indexes are not\nimpacted. Let's fix this now.\n\n[1] https://lore.kernel.org/r/000000000000ec75b005ee97fbaa@google.com"
}
],
"lastModified": "2026-08-04T10:19:30.863",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}