Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52852

21
FAUCET Score

CVE-2023-52852 describes a use-after-free vulnerability in the f2fs file system's compression mechanism within the Linux kernel. Specifically, the f2fs_read_multi_pages() function could attempt to access a deallocated 'dic' pointer if a cached page was hit during decompression, leading to system instability. This vulnerability is rated High severity (CVSS 7.8) due to its potential for high impact on confidentiality, integrity, and availability, and can be exploited locally with low attack complexity and privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.13.19, < 5.14CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.13.19, < 5.15.139CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.63CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.5.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6, < 6.6.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 47th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-52852Moderate

kernel: f2fs: compress: fix to avoid use-after-free on dic

May 21, 2024

References

git.kernel.org / stable/c/8c4504cc0c64862740a6acb301e0cfa59580dbc5
Patch
git.kernel.org / stable/c/932ddb5c29e884cc6fac20417ece72ba4a35c401
Patch
git.kernel.org / stable/c/9375ea7f269093d7c884857ae1f47633a91f429c
Patch
git.kernel.org / stable/c/9d065aa52b6ee1b06f9c4eca881c9b4425a12ba2
Patch
git.kernel.org / stable/c/b0327c84e91a0f4f0abced8cb83ec86a7083f086
Patch