CVE-2023-52526
MEDIUMLinux Kernel - Use-After-Free in EROFS LZMA Global Compressed Deduplication
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: erofs: fix memory leak of LZMA global compressed deduplication When stressing microLZMA EROFS images with the new global compressed deduplication feature enabled (`-Ededupe`), I found some short-lived temporary pages weren't properly released, which could slowly cause unexpected OOMs hours later. Let's fix it now (LZ4 and DEFLATE don't have this issue.)
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
12.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (10)
Linux/Linux
< 6.1
Linux/Linux
5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - 6a5a8f0a9740f865693d5aa97a42cc4504538e18
Linux/Linux
5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - 75a5221630fe5aa3fedba7a06be618db0f79ba1e
Linux/Linux
5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - c955751cbf864cf2055117dd3fe7f780d2a57b56
Linux/Linux
6.1
Linux/Linux
6.1.57 - 6.1.*
Linux/Linux
6.5.7 - 6.5.*
Linux/Linux
6.6
linux/linux_kernel
6.6 rc1 (4 CPE variants)
linux/linux_kernel
6.1 - 6.1.57
Published
Mar 02, 2024
Tracked Since
Feb 18, 2026