Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2023-52582
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-52582 is a vulnerability in the Linux kernel's netfs component, discovered and disclosed on March 2, 2024. The issue affects Linux kernel versions from 5.13 through 6.1.56, 6.2 through 6.5.6, and specific release candidates 6.6-rc1 and 6.6-rc2. The vulnerability occurs when a network filesystem using netfs implements a clamp_length() function that can set subrequest lengths smaller than a page size (NVD).

Technical details

The vulnerability stems from an improper loop implementation in the netfs_rreq_unlock_folios() function. When processing folios to be written back, the function incorrectly calls folio_start_fscache() multiple times for each folio instead of ensuring a single call. This issue has a CVSS v3.1 Base Score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, the vulnerability triggers a kernel oops due to a VM_BUG_ON_FOLIO check failure, potentially leading to system availability issues. This occurs specifically when using network filesystems with specific mount options and file operations (Kernel Patch).

Exploitability

The vulnerability can be triggered through a simple test case involving mounting a network filesystem with specific options (fsc,rsize=1024,wsize=1024) and performing basic file operations. The exploit requires local access and low privileges to execute (NVD).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel. The fix involves modifying the netfs_rreq_unlock_folios() function to ensure folio_start_fscache() is called only once for each folio by introducing a boolean flag to track the state (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management