🛡️ CVE-2023-52759 — linux

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved:

gfs2: ignore negated quota changes

When lots of quota changes are made, there may be cases in which an

inode's quota information is increased and then decreased, such as when

blocks are added to a file, then deleted from it. If the timing is

right, function do_qc can add pending quota changes to a transaction,

then later, another call to do_qc can negate those changes, resulting

in a net gain of 0. The quota_change information is recorded in the qc

buffer (and qd element of the inode as well). The buffer is added to the

transaction by the first call to do_qc, but a subsequent call changes

the value from non-zero back to zero. At that point it's too late to

remove the buffer_head from the transaction. Later, when the quota sync

code is called, the zero-change qd element is discovered and flagged as

an assert warning. If the fs is mounted with errors=panic, the kernel

will panic.

This is usually seen when files are truncated and the quota changes are

negated by punch_hole/truncate which uses gfs2_quota_hold and

gfs2_quota_unhold rather than block allocations that use gfs2_quota_lock

and gfs2_quota_unlock which automatically do quota sync.

This patch solves the problem by adding a check to qd_check_sync such

that net-zero quota changes already added to the transaction are no

longer deemed necessary to be synced, and skipped.

In this case references are taken for the qd and the slot from do_qc

so those need to be put. The normal sequence of events for a normal

non-zero quota change is as follows:

gfs2_quota_change

do_qc

qd_hold

slot_hold

Later, when the changes are to be synced:

gfs2_quota_sync

qd_fish

qd_check_sync

gets qd ref via lockref_get_not_dead

do_sync

do_qc(QC_SYNC)

qd_put

lockref_put_or_lock

qd_unlock

qd_put

lockref_put_or_lock

In the net-zero change case, we add a check to qd_check_sync so it puts

the qd and slot references acquired in gfs2_quota_change and skip the

unneeded sync.

Affected software

CVE-2023-52759 is recorded against 2 packages.

  • linux (fixed in 6.6.8-1)
  • unknown

Timeline and source

Published on 21 May 2024 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
security-tracker.debian.org (Advisory)

CVE-2023-52759 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2024-05-21
Updated 2026-08-12
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 6.6.8-1
unknown

References

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2023-52759?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2023-52759 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.