UBUNTU-CVE-2023-52436
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always zeroed.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- ubuntu•linux
all | < 4.4.0-257.291 | < 4.15.0-227.239 | < 5.4.0-176.196 | < 5.15.0-102.112
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 4.4.0-1134.140 | < 4.4.0-1172.187 | < 4.15.0-1170.183 | < 5.4.0-1122.132 | < 5.15.0-1057.63
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1057.63~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1122.132~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
< 6.5.0-1017.17~22.04.2
- ubuntu•linux-aws-fips
< 4.15.0-2109.115 | all | < 5.4.0-1122.132+fips1 | < 5.15.0-1057.63+fips1
- ubuntu•linux-aws-hwe
< 4.15.0-1170.183~16.04.1
- ubuntu•linux-azure
< 4.15.0-1179.194~14.04.1 | < 4.15.0-1179.194~16.04.1 | all | < 5.4.0-1127.134 | < 5.15.0-1060.69
- ubuntu•linux-azure-4.15
< 4.15.0-1179.194
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1060.69~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1127.134~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
< 6.5.0-1018.19~22.04.2
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | < 5.15.0-1060.69.1 | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
< 4.15.0-2088.94 | all | < 5.4.0-1127.134+fips1 | < 5.15.0-1060.69+fips1
- ubuntu•linux-bluefield
< 5.15.0-1040.42 | < 5.4.0-1082.89 | < 5.15.0-1040.42
- ubuntu•linux-fips
< 4.4.0-1103.110 | all | < 4.15.0-1125.136 | < 5.4.0-1096.106 | < 5.15.0-102.112+fips1
- ubuntu•linux-gcp
< 4.15.0-1164.181~16.04.1 | all | < 5.4.0-1126.135 | < 5.15.0-1055.63
- ubuntu•linux-gcp-4.15
< 4.15.0-1164.181
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1055.63~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1126.135~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
< 6.5.0-1017.17~22.04.1
- ubuntu•linux-gcp-fips
< 4.15.0-2072.77 | all | < 5.4.0-1126.135+fips1 | < 5.15.0-1055.63+fips2
- ubuntu•linux-gke
all | < 5.15.0-1054.59
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
all
- ubuntu•linux-gke-5.4
all
Showing first 50 affected entries in server-rendered view.
References (23)
- https://ubuntu.com/security/CVE-2023-52436
- https://git.kernel.org/linus/e26b6d39270f5eab0087453d9b544189a38c8564
- https://git.kernel.org/stable/c/16ae3132ff7746894894927c1892493693b89135
- https://git.kernel.org/stable/c/12cf91e23b126718a96b914f949f2cdfeadc7b2a
- https://git.kernel.org/stable/c/3e47740091b05ac8d7836a33afd8646b6863ca52
- https://git.kernel.org/stable/c/32a6cfc67675ee96fe107aeed5af9776fec63f11
- https://git.kernel.org/stable/c/5de9e9dd1828db9b8b962f7ca42548bd596deb8a
- https://git.kernel.org/stable/c/2525d1ba225b5c167162fa344013c408e8b4de36
- https://git.kernel.org/stable/c/f6c30bfe5a49bc38cae985083a11016800708fea
- https://git.kernel.org/stable/c/e26b6d39270f5eab0087453d9b544189a38c8564
- https://ubuntu.com/security/notices/USN-6688-1
- https://ubuntu.com/security/notices/USN-6724-1
- https://ubuntu.com/security/notices/USN-6725-1
- https://ubuntu.com/security/notices/USN-6726-1
- https://www.cve.org/CVERecord?id=CVE-2023-52436
- https://ubuntu.com/security/notices/USN-6724-2
- https://ubuntu.com/security/notices/USN-6725-2
- https://ubuntu.com/security/notices/USN-6726-2
- https://ubuntu.com/security/notices/USN-6726-3
- https://ubuntu.com/security/notices/USN-6926-1
- https://ubuntu.com/security/notices/USN-6938-1
- https://ubuntu.com/security/notices/USN-6926-2
- https://ubuntu.com/security/notices/USN-6926-3