CVE-2023-52983

HIGH

Linux kernel 5.15.86-5.15.92 - Use-After-Free in BFQ Block Scheduler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix uaf for bfqq in bic_set_bfqq() After commit 64dc8c732f5c ("block, bfq: fix possible uaf for 'bfqq->bic'"), bic->bfqq will be accessed in bic_set_bfqq(), however, in some context bic->bfqq will be freed, and bic_set_bfqq() is called with the freed bic->bfqq. Fix the problem by always freeing bfqq after bic_set_bfqq().

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 15.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (10)
Linux/Linux 094f3d9314d67691cb21ba091c1b528f6e3c4893 - 511c922c5bf6c8a166bea826e702336bc2424140
Linux/Linux 5.15.86 - 5.15.93
Linux/Linux 5533742c7cb1bc9b1f0bf401cc397d44a3a9e07a - 7f77f3dab5066a7c9da73d72d1eee895ff84a8d5
Linux/Linux 6.0.16 - 6.1
Linux/Linux 6.1.2 - 6.1.11
Linux/Linux 64dc8c732f5c2b406cc752e6aaa1bd5471159cab - b600de2d7d3a16f9007fad1bdae82a3951a26af2
Linux/Linux 761564d93c8265f65543acf0a576b32d66bfa26a - cb1876fc33af26d00efdd473311f1b664c77c44e
Linux/Linux b22fd72bfebda3956efc4431b60ddfc0a51e03e0
linux/linux_kernel 6.0.16
linux/linux_kernel 5.15.86 - 5.15.93
Published Mar 27, 2025
Tracked Since Feb 18, 2026