{"id":"DEBIAN-CVE-2023-53513","details":"In the Linux kernel, the following vulnerability has been resolved:  nbd: fix incomplete validation of ioctl arg  We tested and found an alarm caused by nbd_ioctl arg without verification. The UBSAN warning calltrace like below:  UBSAN: Undefined behaviour in fs/buffer.c:1709:35 signed integer overflow: -9223372036854775808 - 1 cannot be represented in type 'long long int' CPU: 3 PID: 2523 Comm: syz-executor.0 Not tainted 4.19.90 #1 Hardware name: linux,dummy-virt (DT) Call trace:  dump_backtrace+0x0/0x3f0 arch/arm64/kernel/time.c:78  show_stack+0x28/0x38 arch/arm64/kernel/traps.c:158  __dump_stack lib/dump_stack.c:77 [inline]  dump_stack+0x170/0x1dc lib/dump_stack.c:118  ubsan_epilogue+0x18/0xb4 lib/ubsan.c:161  handle_overflow+0x188/0x1dc lib/ubsan.c:192  __ubsan_handle_sub_overflow+0x34/0x44 lib/ubsan.c:206  __block_write_full_page+0x94c/0xa20 fs/buffer.c:1709  block_write_full_page+0x1f0/0x280 fs/buffer.c:2934  blkdev_writepage+0x34/0x40 fs/block_dev.c:607  __writepage+0x68/0xe8 mm/page-writeback.c:2305  write_cache_pages+0x44c/0xc70 mm/page-writeback.c:2240  generic_writepages+0xdc/0x148 mm/page-writeback.c:2329  blkdev_writepages+0x2c/0x38 fs/block_dev.c:2114  do_writepages+0xd4/0x250 mm/page-writeback.c:2344  The reason for triggering this warning is __block_write_full_page() -\u003e i_size_read(inode) - 1 overflow. inode-\u003ei_size is assigned in __nbd_ioctl() -\u003e nbd_set_size() -\u003e bytesize. We think it is necessary to limit the size of arg to prevent errors.  Moreover, __nbd_ioctl() -\u003e nbd_add_socket(), arg will be cast to int. Assuming the value of arg is 0x80000000000000001) (on a 64-bit machine), it will become 1 after the coercion, which will return unexpected results.  Fix it by adding checks to prevent passing in too large numbers.","modified":"2026-09-15T09:02:51.439985826Z","published":"2025-10-01T12:15:55.317Z","upstream":["CVE-2023-53513"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53513"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.37-1"}]}],"versions":["6.1.27-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53513.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53513.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53513.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}