CVE-2023-52600
In the Linux kernel, the following vulnerability has been resolved: jfs: fix uaf in jfs_evict_inode When the execution of diMount(ipimap) fails, the object ipimap that has been released may be accessed in diFreeSpecial().
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: jfs: fix uaf in jfs_evict_inode When the execution of diMount(ipimap) fails, the object ipimap that has been released may be accessed in diFreeSpecial(). Asynchronous ipimap release occurs when rcu_core() calls jfs_free_node(). Therefore, when diMount(ipimap) fails, sbi->ipimap should not be initialized as ipimap.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1696d6d7d4a1b373e96428d0fe1166bd7c3c795ePatch
- https://git.kernel.org/stable/c/32e8f2d95528d45828c613417cb2827d866cbdcePatch
- https://git.kernel.org/stable/c/81b4249ef37297fb17ba102a524039a05c6c5d35Patch
- https://git.kernel.org/stable/c/8e44dc3f96e903815dab1d74fff8faafdc6feb61Patch
- https://git.kernel.org/stable/c/93df0a2a0b3cde2d7ab3a52ed46ea1d6d4aaba5fPatch
- https://git.kernel.org/stable/c/bacdaa04251382d7efd4f09f9a0686bfcc297e2ePatch
- https://git.kernel.org/stable/c/bc6ef64dbe71136f327d63b2b9071b828af2c2a8Patch
- https://git.kernel.org/stable/c/e0e1958f4c365e380b17ccb35617345b31ef7bf3Patch
- https://git.kernel.org/stable/c/1696d6d7d4a1b373e96428d0fe1166bd7c3c795ePatch
- https://git.kernel.org/stable/c/32e8f2d95528d45828c613417cb2827d866cbdcePatch
- https://git.kernel.org/stable/c/81b4249ef37297fb17ba102a524039a05c6c5d35Patch
- https://git.kernel.org/stable/c/8e44dc3f96e903815dab1d74fff8faafdc6feb61Patch
- https://git.kernel.org/stable/c/93df0a2a0b3cde2d7ab3a52ed46ea1d6d4aaba5fPatch
- https://git.kernel.org/stable/c/bacdaa04251382d7efd4f09f9a0686bfcc297e2ePatch
- https://git.kernel.org/stable/c/bc6ef64dbe71136f327d63b2b9071b828af2c2a8Patch
- https://git.kernel.org/stable/c/e0e1958f4c365e380b17ccb35617345b31ef7bf3Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.htmlPatch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.