CVE-2023-4389: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.
Affected products
- Linux Linux Kernel: from 5.7, before 5.10.112 (fixed in 5.10.112); from 5.11, before 5.15.35 (fixed in 5.15.35); from 5.16, before 5.17.4 (fixed in 5.17.4)
Published 2023-08-16. Last modified 2026-06-17.