Review reviewHigh

CVE-2023-52436

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always zeroed.

CVSS
7.8
EPSS
0.30%
22.5% percentile
CISA KEV
Not listed
Published
2024.02.21
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.30%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always zeroed.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 16ae3132ff7746894894927c1892493693b89135, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 12cf91e23b126718a96b914f949f2cdfeadc7b2a, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 3e47740091b05ac8d7836a33afd8646b6863ca52, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 32a6cfc67675ee96fe107aeed5af9776fec63f11, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 5de9e9dd1828db9b8b962f7ca42548bd596deb8a, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < 2525d1ba225b5c167162fa344013c408e8b4de36, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < f6c30bfe5a49bc38cae985083a11016800708fea, >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 < e26b6d39270f5eab0087453d9b544189a38c8564, >= 3.8, < 4.19.306, >= 4.20.0 < 5.4.268, >= 5.5.0 < 5.10.209, >= 5.11.0 < 5.15.148, >= 5.16.0 < 6.1.74, >= 6.2.0 < 6.6.13, >= 6.7.0 < 6.7.1
Fixed versions
4.19.306, 5.4.268, 5.10.209, 5.15.148, 6.1.74, 6.6.13, 6.7.1

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2023-52436 — Linux Linux, linux kernel | SECUFOCUS NOW