VDB
CISA-2023-3111
CISA-2023-3111
PUBLISHED
CVSS 7.8 HIGH
Reported by redhat · Published June 5, 2023
A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
Risk Scores
CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Kernel | Kernel version prior to Kernel 6.0-rc2 |
| n/a | Kernel | Kernel version prior to Kernel 6.0-rc2, Kernel version prior to Kernel 6.0-rc2 |
Timeline
- Jun 5, 2023 CVE Published
- Apr 23, 2025 CVE Updated
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory
References
- [debian-lts-announce] 20230727 [SECURITY] [DLA 3508-1] linux security update mailing-list
- DSA-5480 vendor-advisory
- [debian-lts-announce] 20231019 [SECURITY] [DLA 3623-1] linux-5.10 security update mailing-list