{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-52810","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-21T15:19:24.248Z","datePublished":"2024-05-21T15:31:19.629Z","dateUpdated":"2026-08-05T09:11:32.139Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:11:32.139Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/jfs: Add check for negative db_l2nbperpage\n\nl2nbperpage is log2(number of blks per page), and the minimum legal\nvalue should be 0, not negative.\n\nIn the case of l2nbperpage being negative, an error will occur\nwhen subsequently used as shift exponent.\n\nSyzbot reported this bug:\n\nUBSAN: shift-out-of-bounds in fs/jfs/jfs_dmap.c:799:12\nshift exponent -16777216 is negative"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is only reachable after a local mount of an attacker-crafted JFS image (mount → jfs_fill_super → jfs_mount → dbMount, then later dbAlloc/dbFree using BLKTODMAP); fs/jfs has no network or adjacent-protocol entry path.\nAC:L - dn_l2nbperpage is taken verbatim from the on-disk bmap descriptor into a signed int, so the attacker sets a negative shift amount deterministically; any subsequent allocation/free that calls BLKTODMAP hits the bug with no race or attacker-uncontrollable state.\nPR:L - As with sibling JFS crafted-image CVEs (e.g. CVE-2023-53222), an unprivileged local session user can attach the malicious image via udisks2/polkit/automount on desktops, kiosks, and shared workstations, then trigger dbAlloc/dbFree with ordinary file operations.\nUI:N - The attacker supplies the image, causes it to be mounted (including via automount/udisks on their own session), and drives allocation/free themselves; no separate victim action is required at exploitation time.\nS:U - Wrong metapage selection and allocator/metadata corruption remain inside the host kernel’s security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary impact.\nC:H - A negative db_l2nbperpage makes BLKTODMAP compute attacker-influenced logical block numbers so dbAlloc/dbFree read the wrong (still attacker-controlled) dmap metapage and walk its summary tree/bitmaps, enabling out-of-bounds reads that can be leveraged for disclosure.\nI:H - Subsequent dbAllocNext/dbAllocDmap/dbFreeDmap paths write wmap/tree/nfree and in-memory bmap state based on that wrong page and undefined shift results, corrupting heap-backed metapage and allocator state into a write primitive suitable for control-flow hijacking.\nA:H - Syzbot reported UBSAN shift-out-of-bounds in dbAlloc (panic under UBSAN_TRAP/panic_on_warn), and the corrupted metapage/allocator paths also produce kernel oopses and jfs_error filesystem shutdown."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/jfs/jfs_dmap.c"],"versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cc61fcf7d1c99f148fe8ddfb5c6ed0bb75861f01","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8f2964df6bfce9d92d81ca552010b8677af8d9dc","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a81a56b4cbe3142cc99f6b98e8f9b3a631c768e1","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"524b4f203afcf87accfe387e846f33f916f0c907","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5f148b16972e5f4592629b244d5109b15135f53f","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0cb567e727339a192f9fd0db00781d73a91d15a6","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"491085258185ffc4fb91555b0dba895fe7656a45","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1a7c53fdea1d189087544d9a606d249e93c4934b","status":"affected","versionType":"git"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"525b861a008143048535011f3816d407940f4bfa","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/jfs/jfs_dmap.c"],"versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","status":"unaffected","versionType":"semver"},{"version":"4.14.331","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.300","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.262","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.202","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.140","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.64","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.5.13","lessThanOrEqual":"6.5.*","status":"unaffected","versionType":"semver"},{"version":"6.6.3","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"4.14.331"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"4.19.300"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.4.262"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.10.202"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"5.15.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.1.64"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.5.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.6.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12","versionEndExcluding":"6.7"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/cc61fcf7d1c99f148fe8ddfb5c6ed0bb75861f01"},{"url":"https://git.kernel.org/stable/c/8f2964df6bfce9d92d81ca552010b8677af8d9dc"},{"url":"https://git.kernel.org/stable/c/a81a56b4cbe3142cc99f6b98e8f9b3a631c768e1"},{"url":"https://git.kernel.org/stable/c/524b4f203afcf87accfe387e846f33f916f0c907"},{"url":"https://git.kernel.org/stable/c/5f148b16972e5f4592629b244d5109b15135f53f"},{"url":"https://git.kernel.org/stable/c/0cb567e727339a192f9fd0db00781d73a91d15a6"},{"url":"https://git.kernel.org/stable/c/491085258185ffc4fb91555b0dba895fe7656a45"},{"url":"https://git.kernel.org/stable/c/1a7c53fdea1d189087544d9a606d249e93c4934b"},{"url":"https://git.kernel.org/stable/c/525b861a008143048535011f3816d407940f4bfa"}],"title":"fs/jfs: Add check for negative db_l2nbperpage","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1335","lang":"en","description":"CWE-1335 Incorrect Bitwise Shift of Integer"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"cc61fcf7d1c9","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"8f2964df6bfc","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"a81a56b4cbe3","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"524b4f203afc","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"5f148b16972e","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"0cb567e72733","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"491085258185","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"1a7c53fdea1d","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1da177e4c3f4","status":"affected","lessThan":"525b861a0081","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"4.14.331","status":"unaffected","lessThanOrEqual":"4.14.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"4.19.300","status":"unaffected","lessThanOrEqual":"4.19.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"5.4.262","status":"unaffected","lessThanOrEqual":"5.4.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"5.10.202","status":"unaffected","lessThanOrEqual":"5.10.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"5.15.140","status":"unaffected","lessThanOrEqual":"5.15.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"6.1.64","status":"unaffected","lessThanOrEqual":"6.1.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"6.5.13","status":"unaffected","lessThanOrEqual":"6.5.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"6.6.3","status":"unaffected","lessThanOrEqual":"6.6.*","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"6.7","status":"unaffected"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.4,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-05T16:17:58.719311Z","id":"CVE-2023-52810","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-05T17:20:18.215Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T23:11:36.035Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/cc61fcf7d1c99f148fe8ddfb5c6ed0bb75861f01","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/8f2964df6bfce9d92d81ca552010b8677af8d9dc","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/a81a56b4cbe3142cc99f6b98e8f9b3a631c768e1","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/524b4f203afcf87accfe387e846f33f916f0c907","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/5f148b16972e5f4592629b244d5109b15135f53f","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0cb567e727339a192f9fd0db00781d73a91d15a6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/491085258185ffc4fb91555b0dba895fe7656a45","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/1a7c53fdea1d189087544d9a606d249e93c4934b","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/525b861a008143048535011f3816d407940f4bfa","tags":["x_transferred"]}]}]}}