CVE-2023-52896 describes a NULL pointer dereference vulnerability in the Linux kernel's Btrfs filesystem, specifically affecting the quota rescan functionality. This flaw occurs due to a race condition between a quota rescan operation and a quota disable operation. If exploited, this vulnerability could lead to a denial of service (system crash) on affected Linux systems. The vulnerability has a CVSS score of 4.7 (Medium), indicating a local attack vector with high attack complexity and a high impact on availability. While it requires low privileges to trigger, the specific timing of the race condition makes it challenging to reliably exploit. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low level of public awareness and interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.99, < 5.10.165CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.22, < 5.15.90CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16.8, < 5.17CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.178, < 5.4.230CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.178, < 5.4.230CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.