CVE-2023-52526

MEDIUM

Linux Kernel - Use-After-Free in EROFS LZMA Global Compressed Deduplication

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: erofs: fix memory leak of LZMA global compressed deduplication When stressing microLZMA EROFS images with the new global compressed deduplication feature enabled (`-Ededupe`), I found some short-lived temporary pages weren't properly released, which could slowly cause unexpected OOMs hours later. Let's fix it now (LZ4 and DEFLATE don't have this issue.)

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (10)
Linux/Linux < 6.1
Linux/Linux 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - 6a5a8f0a9740f865693d5aa97a42cc4504538e18
Linux/Linux 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - 75a5221630fe5aa3fedba7a06be618db0f79ba1e
Linux/Linux 5c2a64252c5dc4cfe78e5b2a531c118894e3d155 - c955751cbf864cf2055117dd3fe7f780d2a57b56
Linux/Linux 6.1
Linux/Linux 6.1.57 - 6.1.*
Linux/Linux 6.5.7 - 6.5.*
Linux/Linux 6.6
linux/linux_kernel 6.6 rc1 (4 CPE variants)
linux/linux_kernel 6.1 - 6.1.57
Published Mar 02, 2024
Tracked Since Feb 18, 2026