{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-52591","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-03-02T21:55:42.570Z","datePublished":"2024-03-06T06:45:23.480Z","dateUpdated":"2026-08-05T09:10:32.439Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:10:32.439Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nreiserfs: Avoid touching renamed directory if parent does not change\n\nThe VFS will not be locking moved directory if its parent does not\nchange. Change reiserfs rename code to avoid touching renamed directory\nif its parent does not change as without locking that can corrupt the\nfilesystem."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only via local rename(2)/renameat2 on a mounted reiserfs volume (vfs_rename → reiserfs_rename); reiserfs is a block filesystem (FS_REQUIRES_DEV) with no in-protocol network entry point of its own.\nAC:L - The attacker fully controls both sides of the race by concurrently renaming a subdirectory within the same parent and creating/unlinking entries inside it, so success does not depend on victim state or other attacker-uncontrollable conditions.\nPR:L - Triggering requires only an unprivileged local user with write+exec on a parent directory on a mounted reiserfs filesystem (ordinary rename permission checks); CAP_SYS_ADMIN is not required once the volume is available, including via realistic desktop automount/udisks scenarios.\nUI:N - The attacker performs the concurrent rename and directory-modifying syscalls themselves on a filesystem they can access; no separate victim interaction is required at exploitation time.\nS:U - Impact is confined to the host kernel and the mounted reiserfs instance within the same OS security authority; there is no VM escape, IOMMU bypass, or other cross-boundary breakout.\nC:H - Racing unlocked updates of directory/\"..\" tree items can corrupt the global reiserfs B-tree such that subsequent lookups return the wrong objects or blocks, which is reasonably leveraged for disclosure of other users' file contents on the shared volume.\nI:H - The same unlocked rename path can journal stale or misplaced directory-item writes into the shared on-disk tree, corrupting filesystem metadata beyond the attacker's own entries and yielding unauthorized modification of volume-wide integrity.\nA:H - Filesystem tree corruption can render the volume unusable and cause kernel oopses or hangs when later operations walk the damaged metadata, fully denying availability of the system or the mounted filesystem."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/reiserfs/namei.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"17e1361cb91dc1325834da95d2ab532959d2debc","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c04c162f82ac403917780eb6d1654694455d4e7c","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"49db9b1b86a82448dfaf3fcfefcf678dee56c8ed","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/reiserfs/namei.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"6.6.16","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.4","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.7.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/17e1361cb91dc1325834da95d2ab532959d2debc"},{"url":"https://git.kernel.org/stable/c/c04c162f82ac403917780eb6d1654694455d4e7c"},{"url":"https://git.kernel.org/stable/c/49db9b1b86a82448dfaf3fcfefcf678dee56c8ed"}],"title":"reiserfs: Avoid touching renamed directory if parent does not change","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-noinfo Not enough information"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.8,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-03-06T16:59:49.754179Z","id":"CVE-2023-52591","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-01T15:58:18.846Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T23:03:21.118Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/17e1361cb91dc1325834da95d2ab532959d2debc","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c04c162f82ac403917780eb6d1654694455d4e7c","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/49db9b1b86a82448dfaf3fcfefcf678dee56c8ed","tags":["x_transferred"]}]}]}}