CVE-2023-52810
In the Linux kernel, the following vulnerability has been resolved: fs/jfs: Add check for negative db_l2nbperpage l2nbperpage is log2(number of blks per page), and the minimum legal value should be 0, not negative.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: fs/jfs: Add check for negative db_l2nbperpage l2nbperpage is log2(number of blks per page), and the minimum legal value should be 0, not negative. In the case of l2nbperpage being negative, an error will occur when subsequently used as shift exponent. Syzbot reported this bug: UBSAN: shift-out-of-bounds in fs/jfs/jfs_dmap.c:799:12 shift exponent -16777216 is negative
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1335
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0cb567e727339a192f9fd0db00781d73a91d15a6Patch
- https://git.kernel.org/stable/c/1a7c53fdea1d189087544d9a606d249e93c4934bPatch
- https://git.kernel.org/stable/c/491085258185ffc4fb91555b0dba895fe7656a45Patch
- https://git.kernel.org/stable/c/524b4f203afcf87accfe387e846f33f916f0c907Patch
- https://git.kernel.org/stable/c/525b861a008143048535011f3816d407940f4bfaPatch
- https://git.kernel.org/stable/c/5f148b16972e5f4592629b244d5109b15135f53fPatch
- https://git.kernel.org/stable/c/8f2964df6bfce9d92d81ca552010b8677af8d9dcPatch
- https://git.kernel.org/stable/c/a81a56b4cbe3142cc99f6b98e8f9b3a631c768e1Patch
- https://git.kernel.org/stable/c/cc61fcf7d1c99f148fe8ddfb5c6ed0bb75861f01Patch
- https://git.kernel.org/stable/c/0cb567e727339a192f9fd0db00781d73a91d15a6Patch
- https://git.kernel.org/stable/c/1a7c53fdea1d189087544d9a606d249e93c4934bPatch
- https://git.kernel.org/stable/c/491085258185ffc4fb91555b0dba895fe7656a45Patch
- https://git.kernel.org/stable/c/524b4f203afcf87accfe387e846f33f916f0c907Patch
- https://git.kernel.org/stable/c/525b861a008143048535011f3816d407940f4bfaPatch
- https://git.kernel.org/stable/c/5f148b16972e5f4592629b244d5109b15135f53fPatch
- https://git.kernel.org/stable/c/8f2964df6bfce9d92d81ca552010b8677af8d9dcPatch
- https://git.kernel.org/stable/c/a81a56b4cbe3142cc99f6b98e8f9b3a631c768e1Patch
- https://git.kernel.org/stable/c/cc61fcf7d1c99f148fe8ddfb5c6ed0bb75861f01Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.