cbcvebase.
CVE-2023-52526
published 2024-03-02

CVE-2023-52526: In the Linux kernel, the following vulnerability has been resolved: erofs: fix memory leak of LZMA global compressed deduplication When stressing microLZMA…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: erofs: fix memory leak of LZMA global compressed deduplication When stressing microLZMA EROFS images with the new global compressed deduplication feature enabled (`-Ededupe`), I found some short-lived temporary pages weren't properly released, which could slowly cause unexpected OOMs hours later. Let's fix it now (LZ4 and DEFLATE don't have this issue.)

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 < 6a5a8f0a9740f865693d5aa97a42cc4504538e186a5a8f0a9740f865693d5aa97a42cc4504538e18
linuxlinux>= 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 < c955751cbf864cf2055117dd3fe7f780d2a57b56c955751cbf864cf2055117dd3fe7f780d2a57b56
linuxlinux>= 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 < 75a5221630fe5aa3fedba7a06be618db0f79ba1e75a5221630fe5aa3fedba7a06be618db0f79ba1e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 6.1 < 6.1.576.1.57
linuxlinux_kernel>= 6.2 < 6.5.76.5.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.