Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-52444 Details

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir != new_dir && !whiteout) f2fs_set_link(old_inode, old_dir_entry, old_dir_page, new_dir); else f2fs_put_page(old_dir_page, 0); You want correct inumber in the ".." link. And cross-directory rename does move the source to new parent, even if you'd been asked to leave a whiteout in the old place. [1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/ With below testcase, it may cause dirent corruption, due to it missed to call f2fs_set_link() to update ".." link to new directory. - mkdir -p dir/foo - renameat2 -w dir/foo bar [ASSERT] (__chk_dots_dentries:1421) --> Bad inode number[0x4] for '..', parent parent ino is [0x3] [FSCK] other corrupted bugs [Fail]

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://git.kernel.org/stable/c/02160112e6d45c2610b049df6eb693d7a2e57b46 kernel.orgPatch
https://git.kernel.org/stable/c/2fb4867f4405aea8c0519d7d188207f232a57862 kernel.orgPatch
https://git.kernel.org/stable/c/53edb549565f55ccd0bdf43be3d66ce4c2d48b28 kernel.orgPatch
https://git.kernel.org/stable/c/5624a3c1b1ebc8991318e1cce2aa719542991024 kernel.orgPatch
https://git.kernel.org/stable/c/6f866885e147d33efc497f1095f35b2ee5ec7310 kernel.orgPatch

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 4.2.0, < 4.19.306
>= 4.20, < 5.4.268
>= 5.5.0, < 5.10.209
>= 5.11.0, < 5.15.148
>= 5.16.0, < 6.1.75

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-52444
NVD Published Date:
Feb 22, 2024
NVD Last Modified:
Aug 4, 2026
Source:
kernel.org
CVE-2023-52444 Details - Not Deferred