In the Linux kernel, the following vulnerability has been resolved:
udf: Fix uninitialized array access for some pathnames
For filenames that begin with . and are between 2 and 5 characters long, UDF charset conversion code would read uninitialized memory in the output buffer. The only practical impact is that the name may be prepended a "unification hash" when it is not actually needed but still it is good to fix this.
[
{
"id": "CVE-2023-53165-241591b2",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2278.0,
"function_hash": "126501220947154762201571309817004011742"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b37f998d357102e8eb0f8eeb33f03fff22e49cbf"
},
{
"id": "CVE-2023-53165-3228dd51",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d50988da0db167aed6f38685145cb5cd526c4f8"
},
{
"id": "CVE-2023-53165-58912397",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3f1368af47acf4d0b2a5fb0d2c0d6919d2234b6d"
},
{
"id": "CVE-2023-53165-659f552e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@028f6055c912588e6f72722d89c30b401bbcf013"
},
{
"id": "CVE-2023-53165-7537a51d",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4503f6fc95d6dee85fb2c54785848799e192c51c"
},
{
"id": "CVE-2023-53165-a5295914",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d50988da0db167aed6f38685145cb5cd526c4f8"
},
{
"id": "CVE-2023-53165-a77de30f",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@985f9666698960dfc87a106d6314203fa90fda75"
},
{
"id": "CVE-2023-53165-b01b9b8c",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2153.0,
"function_hash": "145933016684871531310645100133112635285"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@008ae78d1e12efa904dc819b1ec83e2bca6b2c56"
},
{
"id": "CVE-2023-53165-c4d6f457",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6824149809395dfbb5bc36bc7057cc3cb84e56d"
},
{
"id": "CVE-2023-53165-c843de4e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4503f6fc95d6dee85fb2c54785848799e192c51c"
},
{
"id": "CVE-2023-53165-cf221589",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@985f9666698960dfc87a106d6314203fa90fda75"
},
{
"id": "CVE-2023-53165-d0b19906",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@028f6055c912588e6f72722d89c30b401bbcf013"
},
{
"id": "CVE-2023-53165-d263fbe3",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b37f998d357102e8eb0f8eeb33f03fff22e49cbf"
},
{
"id": "CVE-2023-53165-dc58156e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 2272.0,
"function_hash": "35564873258954680820357740783894124963"
},
"target": {
"function": "udf_name_from_CS0",
"file": "fs/udf/unicode.c"
},
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@3f1368af47acf4d0b2a5fb0d2c0d6919d2234b6d"
},
{
"id": "CVE-2023-53165-dfec854d",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6824149809395dfbb5bc36bc7057cc3cb84e56d"
},
{
"id": "CVE-2023-53165-fcd040e3",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"301650817144465110837248364159536552154",
"300845262948670949230109971012708773278",
"125546682090024382905246879636046010891",
"99675360879355518401462218759455199386"
],
"threshold": 0.9
},
"target": {
"file": "fs/udf/unicode.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@008ae78d1e12efa904dc819b1ec83e2bca6b2c56"
}
]