cbcvebase.
CVE-2023-3111
published 2023-06-05

CVE-2023-3111: A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.44%
36.3th percentile
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.19.6-1 (bookworm)linux 5.19.6-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.4.0-156.1735.4.0-156.173
linuxlinux_kernel>= 0 < 4.4.0-242.2764.4.0-242.276
linuxlinux_kernel>= 0 < 4.15.0-214.2254.15.0-214.225
linuxlinux_kernel>= 2.6.31 < 4.14.3184.14.318
linuxlinux_kernel>= 4.15 < 4.19.2864.19.286
linuxlinux_kernel>= 4.20 < 5.4.2475.4.247
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4
linuxlinux_kernel>= 5.5 < 5.10.1845.10.184
msrccbl2_kernel_5.15.116.1-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.