cbcvebase.
CVE-2023-52566
published 2024-03-02

CVE-2023-52566: In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() In…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() In nilfs_gccache_submit_read_data(), brelse(bh) is called to drop the reference count of bh when the call to nilfs_dat_translate() fails. If the reference count hits 0 and its owner page gets unlocked, bh may be freed. However, bh->b_page is dereferenced to put the page after that, which may result in a use-after-free bug. This patch moves the release operation after unlocking and putting the page. NOTE: The function in question is only called in GC, and in combination with current userland tools, address translation using DAT does not occur in that function, so the code path that causes this issue will not be executed. However, it is possible to run that code path by intentionally modifying the userland GC library or by calling the GC ioctl directly. [[email protected]: NOTE added to the commit log]

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < fb1084e63ee56958b0a56e17a50a4fd86445b9c1fb1084e63ee56958b0a56e17a50a4fd86445b9c1
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < bb61224f6abc8e71bfdf06d7c984e23460875f5bbb61224f6abc8e71bfdf06d7c984e23460875f5b
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 193b5a1c6c67c36b430989dc063fe7ea4e200a33193b5a1c6c67c36b430989dc063fe7ea4e200a33
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 7130a87ca32396eb9bf48b71a2d42259ae44c6c77130a87ca32396eb9bf48b71a2d42259ae44c6c7
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 3936e8714907cd55e37c7cc50e50229e4a9042e83936e8714907cd55e37c7cc50e50229e4a9042e8
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 980663f1d189eedafd18d80053d9cf3e2ceb5c8c980663f1d189eedafd18d80053d9cf3e2ceb5c8c
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 28df4646ad8b433340772edc90ca709cdefc53e228df4646ad8b433340772edc90ca709cdefc53e2
linuxlinux>= a3d93f709e893187d301aa5458b2248db9f22bd1 < 7ee29facd8a9c5a26079148e36bcf07141b3a6bc7ee29facd8a9c5a26079148e36bcf07141b3a6bc
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 4.4.0-254.2884.4.0-254.288
linuxlinux_kernel>= 0 < 4.15.0-225.2374.15.0-225.237
linuxlinux_kernel>= 2.6.30 < 4.14.3274.14.327
linuxlinux_kernel>= 4.15 < 4.19.2964.19.296
linuxlinux_kernel>= 4.20 < 5.4.2585.4.258
linuxlinux_kernel>= 5.11 < 5.15.1345.15.134
linuxlinux_kernel>= 5.16 < 6.1.566.1.56
linuxlinux_kernel>= 5.5 < 5.10.1985.10.198
linuxlinux_kernel>= 6.2 < 6.5.66.5.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.