CVE-2023-37454: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operation in the udf_put_super and udf_close_lvid functions in fs/udf/super.c. NOTE: the suse.com reference has a different perspective about this.

Affected products

  • Linux Linux Kernel: up to and including 6.4.2

Published 2023-07-06. Last modified 2026-06-17.