CVE-2023-52682
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
17/05/2024
Last modified:
19/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
f2fs: fix to wait on block writeback for post_read case<br />
<br />
If inode is compressed, but not encrypted, it missed to call<br />
f2fs_wait_on_block_writeback() to wait for GCed page writeback<br />
in IPU write path.<br />
<br />
Thread A GC-Thread<br />
- f2fs_gc<br />
- do_garbage_collect<br />
- gc_data_segment<br />
- move_data_block<br />
- f2fs_submit_page_write<br />
migrate normal cluster&#39;s block via<br />
meta_inode&#39;s page cache<br />
- f2fs_write_single_data_page<br />
- f2fs_do_write_data_page<br />
- f2fs_inplace_write_data<br />
- f2fs_submit_page_bio<br />
<br />
IRQ<br />
- f2fs_read_end_io<br />
IRQ<br />
old data overrides new data due to<br />
out-of-order GC and common IO.<br />
- f2fs_read_end_io
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.6 (including) | 6.1.75 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.7.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/4535be48780431753505e74e1b1ad4836a189bc2
- https://git.kernel.org/stable/c/55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00
- https://git.kernel.org/stable/c/9bfd5ea71521d0e522ba581c6ccc5db93759c0c3
- https://git.kernel.org/stable/c/f904c156d8011d8291ffd5b6b398f3747e294986
- https://git.kernel.org/stable/c/4535be48780431753505e74e1b1ad4836a189bc2
- https://git.kernel.org/stable/c/55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00
- https://git.kernel.org/stable/c/9bfd5ea71521d0e522ba581c6ccc5db93759c0c3
- https://git.kernel.org/stable/c/f904c156d8011d8291ffd5b6b398f3747e294986



