CVE-2023-52588

HIGH

Linux Kernel < 5.15.149 - Data Corruption via F2FS Block Migration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to tag gcing flag on page during block migration It needs to add missing gcing flag on page during block migration, in order to garantee migrated data be persisted during checkpoint, otherwise out-of-order persistency between data and node may cause data corruption after SPOR. Similar issue was fixed by commit 2d1fe8a86bf5 ("f2fs: fix to tag gcing flag on page during file defragment").

Scores

CVSS v3 7.1
EPSS 0.0025
EPSS Percentile 16.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (17)
linux/Kernel 3.8.0 - 5.15.149linux
linux/Kernel 5.16.0 - 6.1.77linux
linux/Kernel 6.2.0 - 6.6.16linux
linux/Kernel 6.7.0 - 6.7.4linux
Linux/Linux < 3.8
Linux/Linux 3.8
Linux/Linux 5.15.149 - 5.15.*
Linux/Linux 6.1.77 - 6.1.*
Linux/Linux 6.6.16 - 6.6.*
Linux/Linux 6.7.4 - 6.7.*
... and 7 more
Published Mar 06, 2024
Tracked Since Feb 18, 2026