
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53165 is a use of uninitialized resource vulnerability in the Linux kernel's UDF (Universal Disk Format) filesystem subsystem. The flaw causes the UDF charset conversion code to read uninitialized memory in the output buffer when processing filenames that begin with . and are between 2 and 5 characters long. It affects Linux kernel versions from 4.6 through multiple stable branches, with fixed versions including 4.14.324, 4.19.293, 5.4.255, 5.10.192, 5.15.123, 6.1.42, 6.4.7, and 6.5+. Disclosed on September 15, 2025, it carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).
The root cause is classified as CWE-908 (Use of Uninitialized Resource): the UDF charset conversion code reads from an uninitialized output buffer when handling dot-prefixed filenames of 2–5 characters. The practical consequence is that the filename may be incorrectly prepended with a "unification hash" that is not actually required, due to the uninitialized memory being interpreted as meaningful data. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction, making it exploitable by any local user who can mount or interact with a UDF filesystem. Patches were applied across multiple stable kernel branches via commits to the kernel stable tree (Red Hat CVE, Kernel Patch).
The primary impact of this vulnerability is limited to availability and incorrect filesystem behavior — specifically, filenames beginning with . and 2–5 characters long may be incorrectly prepended with a unification hash, potentially causing file lookup failures or unexpected behavior in applications relying on those filenames. There is no confidentiality or integrity impact beyond this naming anomaly, and no evidence of data exfiltration or privilege escalation risk. The CVSS availability impact is rated High (A:H), suggesting that in certain scenarios the incorrect filename handling could cause denial-of-service conditions for processes depending on UDF-mounted filesystems (Red Hat CVE).
There is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2023-53165. The EPSS score is extremely low at 0.000240, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Qualys and Nessus scanner plugins (Feedly).
The Linux kernel project has released fixes across all affected stable branches. Administrators should update to the following patched versions or later: 4.14.324, 4.19.293, 5.4.255, 5.10.192, 5.15.123, 6.1.42, 6.4.7, or 6.5+. Distribution-specific updates are available from vendors including SUSE (advisories SUSE-2025-20870-1, SUSE-2025-20898-1, SUSE-2025-4057-1, SUSE-2025-4132-1) and Red Hat. As a temporary workaround where patching is not immediately possible, avoiding the mounting of untrusted UDF filesystems reduces exposure (Red Hat CVE, SUSE Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."