CVE-2023-52983: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix uaf for bfqq in bic_set_bfqq() After commit 64dc8c732f5c ("block, bfq: fix possible uaf for 'bfqq->bic'"), bic->bfqq will be accessed in bic_set_bfqq(), however, in some context bic->bfqq will be freed, and bic_set_bfqq() is called with the freed bic->bfqq. Fix the problem by always freeing bfqq after bic_set_bfqq().
Affected products
- Linux Linux Kernel: from 5.15.86, before 5.15.93 (fixed in 5.15.93); from 6.1.2, before 6.1.11 (fixed in 6.1.11); version 6.0.16 only
Published 2025-03-27. Last modified 2026-06-17.