---
id: CVE-2023-52600
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  jfs: fix uaf in jfs_evict_inode

  When the execution of diMount(ipimap) fails, the object ipimap that has been
  released may be accessed in diFreeSpecial()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  jfs: fix uaf in jfs_evict_inode

  When the execution of diMount(ipimap) fails, the object ipimap that has been
  released may be accessed in diFreeSpecial(). Asynchronous …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - linux_kernel < 4.19.307
  - 'linux_kernel >= 4.20, < 5.4.269'
  - 'linux_kernel >= 5.5, < 5.10.210'
  - 'linux_kernel >= 5.11, < 5.15.149'
  - 'linux_kernel >= 5.16, < 6.1.77'
  - 'linux_kernel >= 6.2, < 6.6.16'
  - 'linux_kernel >= 6.7, < 6.7.4'
patched:
  - linux_kernel 6.7.4
published: '2024-03-06'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52600'
references:
  - url: 'https://git.kernel.org/stable/c/1696d6d7d4a1b373e96428d0fe1166bd7c3c795e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/32e8f2d95528d45828c613417cb2827d866cbdce'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/81b4249ef37297fb17ba102a524039a05c6c5d35'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8e44dc3f96e903815dab1d74fff8faafdc6feb61'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/93df0a2a0b3cde2d7ab3a52ed46ea1d6d4aaba5f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bacdaa04251382d7efd4f09f9a0686bfcc297e2e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bc6ef64dbe71136f327d63b2b9071b828af2c2a8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e0e1958f4c365e380b17ccb35617345b31ef7bf3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1696d6d7d4a1b373e96428d0fe1166bd7c3c795e'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/32e8f2d95528d45828c613417cb2827d866cbdce'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/81b4249ef37297fb17ba102a524039a05c6c5d35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/8e44dc3f96e903815dab1d74fff8faafdc6feb61'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/93df0a2a0b3cde2d7ab3a52ed46ea1d6d4aaba5f'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/bacdaa04251382d7efd4f09f9a0686bfcc297e2e'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/bc6ef64dbe71136f327d63b2b9071b828af2c2a8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e0e1958f4c365e380b17ccb35617345b31ef7bf3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00281
epssPercentile: 0.18337
ingestedAt: '2026-08-05T05:58:02.826Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

jfs: fix uaf in jfs_evict_inode

When the execution of diMount(ipimap) fails, the object ipimap that has been
released may be accessed in diFreeSpecial(). Asynchronous ipimap release occurs
when rcu_core() calls jfs_free_node().

Therefore, when diMount(ipimap) fails, sbi->ipimap should not be initialized as
ipimap.

## Affected

- `linux_kernel < 4.19.307`
- `linux_kernel >= 4.20, < 5.4.269`
- `linux_kernel >= 5.5, < 5.10.210`
- `linux_kernel >= 5.11, < 5.15.149`
- `linux_kernel >= 5.16, < 6.1.77`
- `linux_kernel >= 6.2, < 6.6.16`
- `linux_kernel >= 6.7, < 6.7.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.7.4`
