CVE-2023-53672: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: btrfs: output extra debug info if we failed to find an inline backref [BUG] Syzbot reported several warning triggered inside lookup_inline_extent_backref(). [CAUSE] As usual, the reproducer doesn't reliably trigger locally here, but at least we know the WARN_ON() is triggered when an inline backref can not be found, and it can only be triggered when @insert is true. (I.e. inserting a new inline backref, which means the backref should already exist) [ENHANCEMENT] After the WARN_ON(), dump all the parameters and the extent tree leaf to help debug.
Affected products
- Linux Linux Kernel: from 3.9.1, before 4.14.326 (fixed in 4.14.326); from 4.15, before 4.19.295 (fixed in 4.19.295); from 4.20, before 5.4.257 (fixed in 5.4.257); from 5.5, before 5.10.197 (fixed in 5.10.197); from 5.11, before 5.15.133 (fixed in 5.15.133); from 5.16, before 6.1.55 (fixed in 6.1.55); …
Published 2025-10-07. Last modified 2026-06-17.