{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2023-53270",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2023-53270"
  ],
  "published": "2025-09-16T08:07:21Z",
  "summary": "ext4: fix i_disksize exceeding i_size problem in paritally written case",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix i_disksize exceeding i_size problem in paritally written case\n\nIt is possible for i_disksize can exceed i_size, triggering a warning.\n\ngeneric_perform_write\n copied = iov_iter_copy_from_user_atomic(len) // copied < len\n ext4_da_write_end\n | ext4_update_i_disksize\n |  new_i_size = pos + copied;\n |  WRITE_ONCE(EXT4_I(inode)->i_disksize, newsize) // update i_disksize\n | generic_write_end\n |  copied = block_write_end(copied, len) // copied = 0\n |   if (unlikely(copied < len))\n |    if (!PageUptodate(page))\n |     copied = 0;\n |  if (pos + copied > inode->i_size) // return false\n if (unlikely(copied == 0))\n  goto again;\n if (unlikely(iov_iter_fault_in_readable(i, bytes))) {\n  status = -EFAULT;\n  break;\n }\n\nWe get i_disksize greater than i_size here, which could trigger WARNING\ncheck 'i_size_read(inode) < EXT4_I(inode)->i_disksize' while doing dio:\n\next4_dio_write_iter\n iomap_dio_rw\n  __iomap_dio_rw // return err, length is not aligned to 512\n ext4_handle_inode_extension\n  WARN_ON_ONCE(i_size_read(inode) < EXT4_I(inode)->i_disksize) // Oops\n\n WARNING: CPU: 2 PID: 2609 at fs/ext4/file.c:319\n CPU: 2 PID: 2609 Comm: aa Not tainted 6.3.0-rc2\n RIP: 0010:ext4_file_write_iter+0xbc7\n Call Trace:\n  vfs_write+0x3b1\n  ksys_write+0x77\n  do_syscall_64+0x39\n\nFix it by updating 'copied' value before updating i_disksize just like\next4_write_inline_data_end() does.\n\nA reproducer can be found in the buganizer link below.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.1.21-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v6",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v7l",
            "binary_version": "1:6.1.21-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.1.0-rpi1-rpi-v8",
            "binary_version": "1:6.1.21-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.1.21-1+rpt1": {
            "linux_commit": "0afb5e98488aed7017b9bf321b575d0177feb7ed",
            "upstream_version": "6.1.21",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.1.28"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-53270"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/18eb23891aeae3229baf8c7c23b76be3364e1967"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/d30090eb546d993ea3f3023452540c476ea614a5"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/3ecea2fee14227712694c8b54ad99d471e61de92"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/53877ed201baa6b58f7ce9df92664a839113c30e"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/1dedde690303c05ef732b7c5c8356fdf60a4ade3"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-05-12T04:54:46Z"
  }
}
