CVE-2023-52804: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: fs/jfs: Add validity check for db_maxag and db_agpref Both db_maxag and db_agpref are used as the index of the db_agfree array, but there is currently no validity check for db_maxag and db_agpref, which can lead to errors. The following is related bug reported by Syzbot: UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:639:20 index 7936 is out of range for type 'atomic_t[128]' Add checking that the values of db_maxag and db_agpref are valid indexes for the db_agfree array.
Affected products
- Linux Linux Kernel: before 4.14.331 (fixed in 4.14.331); from 4.15, before 4.19.300 (fixed in 4.19.300); from 4.20, before 5.4.262 (fixed in 5.4.262); from 5.5, before 5.10.202 (fixed in 5.10.202); from 5.11, before 5.15.140 (fixed in 5.15.140); from 5.16, before 6.1.64 (fixed in 6.1.64); …
Published 2024-05-21. Last modified 2026-08-04.