U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NOTICE UPDATED - April, 25th 2024

NIST has updated the NVD program announcement page with additional information regarding recent concerns and the temporary delays in enrichment efforts.

CVE-2023-52436 Detail

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always zeroed.


Severity



CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score:  7.8 HIGH
Vector:  CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H


NVD Analysts use publicly available information to associate vector strings and CVSS scores. We also display any CVSS information provided within the CVE List from the CNA.

Note: NVD Analysts have published a CVSS score for this CVE based on publicly available information at the time of analysis. The CNA has not provided a score within the CVE List.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
https://git.kernel.org/stable/c/12cf91e23b126718a96b914f949f2cdfeadc7b2a Patch 
https://git.kernel.org/stable/c/16ae3132ff7746894894927c1892493693b89135 Patch 
https://git.kernel.org/stable/c/2525d1ba225b5c167162fa344013c408e8b4de36 Patch 
https://git.kernel.org/stable/c/32a6cfc67675ee96fe107aeed5af9776fec63f11 Patch 
https://git.kernel.org/stable/c/3e47740091b05ac8d7836a33afd8646b6863ca52 Patch 
https://git.kernel.org/stable/c/5de9e9dd1828db9b8b962f7ca42548bd596deb8a Patch 
https://git.kernel.org/stable/c/e26b6d39270f5eab0087453d9b544189a38c8564 Patch 
https://git.kernel.org/stable/c/f6c30bfe5a49bc38cae985083a11016800708fea Patch 

Weakness Enumeration

CWE-ID CWE Name Source
NVD-CWE-Other Other cwe source acceptance level NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

2 change records found show changes

Quick Info

CVE Dictionary Entry:
CVE-2023-52436
NVD Published Date:
02/20/2024
NVD Last Modified:
04/19/2024
Source:
kernel.org