cbcvebase.
CVE-2023-52805
published 2024-05-21

CVE-2023-52805: In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diAlloc Currently there is not check against the agno…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diAlloc Currently there is not check against the agno of the iag while allocating new inodes to avoid fragmentation problem. Added the check which is required.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2308d0fb0dc32446b4e6ca37cd09c30374bb64e92308d0fb0dc32446b4e6ca37cd09c30374bb64e9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < cf7e3e84df36a9953796c737f080712f631d7083cf7e3e84df36a9953796c737f080712f631d7083
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7467ca10a5ff09b0e87edf6c4d2a4bfdee69cf2c7467ca10a5ff09b0e87edf6c4d2a4bfdee69cf2c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1ba7df5457dc1c1071c5f92ac11323533a6430e11ba7df5457dc1c1071c5f92ac11323533a6430e1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 64f062baf202b82f54987a3f614a6c8f3e46664164f062baf202b82f54987a3f614a6c8f3e466641
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8c68af2af697ba2ba3b138be0c6d72e2ce3a3d6d8c68af2af697ba2ba3b138be0c6d72e2ce3a3d6d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 665b44e55c2767a4f899c3b18f49e9e1c9983777665b44e55c2767a4f899c3b18f49e9e1c9983777
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1708d0a9917fea579cc9da3d87b154285abd2cd81708d0a9917fea579cc9da3d87b154285abd2cd8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 05d9ea1ceb62a55af6727a69269a4fd310edf48305d9ea1ceb62a55af6727a69269a4fd310edf483
linuxlinux_kernel< 4.14.3314.14.331
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 4.15 < 4.19.3004.19.300
linuxlinux_kernel>= 4.20 < 5.4.2625.4.262
linuxlinux_kernel>= 5.11 < 5.15.1405.15.140
linuxlinux_kernel>= 5.16 < 6.1.646.1.64
linuxlinux_kernel>= 5.5 < 5.10.2025.10.202
linuxlinux_kernel>= 6.2 < 6.5.136.5.13
linuxlinux_kernel>= 6.6 < 6.6.36.6.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.