{"id":"CVE-2023-53165","summary":"udf: Fix uninitialized array access for some pathnames","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix uninitialized array access for some pathnames\n\nFor filenames that begin with . and are between 2 and 5 characters long,\nUDF charset conversion code would read uninitialized memory in the\noutput buffer. The only practical impact is that the name may be prepended a\n\"unification hash\" when it is not actually needed but still it is good\nto fix this.","modified":"2026-04-02T09:43:42.580425Z","published":"2025-09-15T14:03:53.987Z","related":["SUSE-SU-2025:03600-1","SUSE-SU-2025:03614-1","SUSE-SU-2025:03615-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:03634-1","SUSE-SU-2025:20851-1","SUSE-SU-2025:20861-1","SUSE-SU-2025:20870-1","SUSE-SU-2025:20898-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3751-1","SUSE-SU-2025:3761-1","SUSE-SU-2025:4057-1","SUSE-SU-2025:4132-1","SUSE-SU-2025:4141-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53165.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/008ae78d1e12efa904dc819b1ec83e2bca6b2c56"},{"type":"WEB","url":"https://git.kernel.org/stable/c/028f6055c912588e6f72722d89c30b401bbcf013"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3f1368af47acf4d0b2a5fb0d2c0d6919d2234b6d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4503f6fc95d6dee85fb2c54785848799e192c51c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4d50988da0db167aed6f38685145cb5cd526c4f8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/985f9666698960dfc87a106d6314203fa90fda75"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a6824149809395dfbb5bc36bc7057cc3cb84e56d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b37f998d357102e8eb0f8eeb33f03fff22e49cbf"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53165.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53165"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"484a10f49387e4386bf2708532e75bf78ffea2cb"},{"fixed":"008ae78d1e12efa904dc819b1ec83e2bca6b2c56"},{"fixed":"b37f998d357102e8eb0f8eeb33f03fff22e49cbf"},{"fixed":"3f1368af47acf4d0b2a5fb0d2c0d6919d2234b6d"},{"fixed":"4503f6fc95d6dee85fb2c54785848799e192c51c"},{"fixed":"985f9666698960dfc87a106d6314203fa90fda75"},{"fixed":"a6824149809395dfbb5bc36bc7057cc3cb84e56d"},{"fixed":"4d50988da0db167aed6f38685145cb5cd526c4f8"},{"fixed":"028f6055c912588e6f72722d89c30b401bbcf013"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53165.json"}}],"schema_version":"1.7.5"}