cbcvebase.
CVE-2023-52682
published 2024-05-17

CVE-2023-52682: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read case If inode is compressed, but not…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read case If inode is compressed, but not encrypted, it missed to call f2fs_wait_on_block_writeback() to wait for GCed page writeback in IPU write path. Thread A GC-Thread - f2fs_gc - do_garbage_collect - gc_data_segment - move_data_block - f2fs_submit_page_write migrate normal cluster's block via meta_inode's page cache - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_submit_page_bio IRQ - f2fs_read_end_io IRQ old data overrides new data due to out-of-order GC and common IO. - f2fs_read_end_io

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 2bfe8fdb674f71747553a65f2ef27e14c88806552bfe8fdb674f71747553a65f2ef27e14c8880655
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 9bfd5ea71521d0e522ba581c6ccc5db93759c0c39bfd5ea71521d0e522ba581c6ccc5db93759c0c3
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 4535be48780431753505e74e1b1ad4836a189bc24535be48780431753505e74e1b1ad4836a189bc2
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < f904c156d8011d8291ffd5b6b398f3747e294986f904c156d8011d8291ffd5b6b398f3747e294986
linuxlinux>= 4c8ff7095bef64fc47e996a938f7d57f9e077da3 < 55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa0055fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 5.6 < 6.1.756.1.75
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure-5.15
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips
ubuntulinux-gke

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.5HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.