SB20250916261 - Use of uninitialized resource in Linux kernel udf
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2023-53165)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the udf_name_from_CS0() function in fs/udf/unicode.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/008ae78d1e12efa904dc819b1ec83e2bca6b2c56
- https://git.kernel.org/stable/c/028f6055c912588e6f72722d89c30b401bbcf013
- https://git.kernel.org/stable/c/3f1368af47acf4d0b2a5fb0d2c0d6919d2234b6d
- https://git.kernel.org/stable/c/4503f6fc95d6dee85fb2c54785848799e192c51c
- https://git.kernel.org/stable/c/4d50988da0db167aed6f38685145cb5cd526c4f8
- https://git.kernel.org/stable/c/985f9666698960dfc87a106d6314203fa90fda75
- https://git.kernel.org/stable/c/a6824149809395dfbb5bc36bc7057cc3cb84e56d
- https://git.kernel.org/stable/c/b37f998d357102e8eb0f8eeb33f03fff22e49cbf
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.293