cbcvebase.
CVE-2023-52799
published 2024-05-21

CVE-2023-52799: In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in dbFindLeaf Currently while searching for dmtree_t for…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in dbFindLeaf Currently while searching for dmtree_t for sufficient free blocks there is an array out of bounds while getting element in tp->dm_stree. To add the required check for out of bound we first need to determine the type of dmtree. Thus added an extra parameter to dbFindLeaf so that the type of tree can be determined and the required check can be applied.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 20f9310a18e3e99fc031e036fcbed67105ae185920f9310a18e3e99fc031e036fcbed67105ae1859
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 86df90f3fea7c5591f05c8a0010871d435e8304686df90f3fea7c5591f05c8a0010871d435e83046
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ecfb47f13b08b02cf28b7b50d4941eefa21954d2ecfb47f13b08b02cf28b7b50d4941eefa21954d2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 81aa58cd8495b8c3b527f58ccbe19478d8087f6181aa58cd8495b8c3b527f58ccbe19478d8087f61
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < da3da5e1e6f71c21d8e6149d7076d936ef5d4cb9da3da5e1e6f71c21d8e6149d7076d936ef5d4cb9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a50b796d36719757526ee094c703378895ab5e67a50b796d36719757526ee094c703378895ab5e67
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 88b7894a8f8705bf4e7ea90b10229376abf1451488b7894a8f8705bf4e7ea90b10229376abf14514
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 87c681ab49e99039ff2dd3e71852417381b1387887c681ab49e99039ff2dd3e71852417381b13878
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 22cad8bc1d36547cdae0eef316c47d917ce3147c22cad8bc1d36547cdae0eef316c47d917ce3147c
linuxlinux_kernel< 4.14.3314.14.331
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 4.4.0-266.3004.4.0-266.300
linuxlinux_kernel>= 0 < 4.15.0-235.2474.15.0-235.247
linuxlinux_kernel>= 4.15 < 4.19.3004.19.300
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1405.15.140
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 5.5 < 5.10.2025.10.202
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.