{"id":"DEBIAN-CVE-2023-53526","details":"In the Linux kernel, the following vulnerability has been resolved:  jbd2: check 'jh-\u003eb_transaction' before removing it from checkpoint  Following process will corrupt ext4 image: Step 1: jbd2_journal_commit_transaction  __jbd2_journal_insert_checkpoint(jh, commit_transaction)  // Put jh into trans1-\u003et_checkpoint_list  journal-\u003ej_checkpoint_transactions = commit_transaction  // Put trans1 into journal-\u003ej_checkpoint_transactions  Step 2: do_get_write_access  test_clear_buffer_dirty(bh) // clear buffer dirty，set jbd dirty  __jbd2_journal_file_buffer(jh, transaction) // jh belongs to trans2  Step 3: drop_cache  journal_shrink_one_cp_list   jbd2_journal_try_remove_checkpoint    if (!trylock_buffer(bh))  // lock bh, true    if (buffer_dirty(bh))     // buffer is not dirty    __jbd2_journal_remove_checkpoint(jh)    // remove jh from trans1-\u003et_checkpoint_list  Step 4: jbd2_log_do_checkpoint  trans1 = journal-\u003ej_checkpoint_transactions  // jh is not in trans1-\u003et_checkpoint_list  jbd2_cleanup_journal_tail(journal)  // trans1 is done  Step 5: Power cut, trans2 is not committed, jh is lost in next mounting.  Fix it by checking 'jh-\u003eb_transaction' before remove it from checkpoint.","modified":"2026-09-15T09:02:51.694786694Z","published":"2025-10-01T12:15:57.177Z","upstream":["CVE-2023-53526"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53526"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.55-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53526.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53526.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53526.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}