{"id":"CVE-2023-53506","summary":"udf: Do not bother merging very long extents","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Do not bother merging very long extents\n\nWhen merging very long extents we try to push as much length as possible\nto the first extent. However this is unnecessarily complicated and not\nreally worth the trouble. Furthermore there was a bug in the logic\nresulting in corrupting extents in the file as syzbot reproducer shows.\nSo just don't bother with the merging of extents that are too long\ntogether.","modified":"2026-04-02T09:44:20.138508Z","published":"2025-10-01T11:45:56.616Z","related":["SUSE-SU-2025:03614-1","SUSE-SU-2025:03615-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3761-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53506.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3d20e3b768aff32112bdce8d3219d923ae75f9f1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/53cafe1d6d8ef9f93318e5bfccc0d24f27d41ced"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5d029799d381a9ee06209a222cae75f04c5d5304"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7a965da79f2d22601f329cbfce588386b0847544"},{"type":"WEB","url":"https://git.kernel.org/stable/c/965982feb333aefa9256c0fe188b5f1b958aef63"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a8d602f0723586e668bae7e65c832ceb9bcc8bc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/adac9ac6d2e04ea0782b91a00ba10706002f3ec4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d52252a1de4cf96a34f722b0cd8902d8ff78eb57"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53506.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53506"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2"},{"fixed":"d52252a1de4cf96a34f722b0cd8902d8ff78eb57"},{"fixed":"5d029799d381a9ee06209a222cae75f04c5d5304"},{"fixed":"3d20e3b768aff32112bdce8d3219d923ae75f9f1"},{"fixed":"965982feb333aefa9256c0fe188b5f1b958aef63"},{"fixed":"9a8d602f0723586e668bae7e65c832ceb9bcc8bc"},{"fixed":"adac9ac6d2e04ea0782b91a00ba10706002f3ec4"},{"fixed":"7a965da79f2d22601f329cbfce588386b0847544"},{"fixed":"53cafe1d6d8ef9f93318e5bfccc0d24f27d41ced"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53506.json"}}],"schema_version":"1.7.5"}