CVE-2023-52748

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-52748
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52748.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52748
Downstream
Published
2024-05-21T15:30:38.229Z
Modified
2025-11-28T02:34:37.128652Z
Summary
f2fs: avoid format-overflow warning
Details

In the Linux kernel, the following vulnerability has been resolved:

f2fs: avoid format-overflow warning

With gcc and W=1 option, there's a warning like this:

fs/f2fs/compress.c: In function ‘f2fsinitpagearraycache’: fs/f2fs/compress.c:1984:47: error: ‘%u’ directive writing between 1 and 7 bytes into a region of size between 5 and 8 [-Werror=format-overflow=] 1984 | sprintf(slabname, "f2fspagearrayentry-%u:%u", MAJOR(dev), MINOR(dev)); | ^~

String "f2fspagearrayentry-%u:%u" can up to 35. The first "%u" can up to 4 and the second "%u" can up to 7, so total size is "24 + 4 + 7 = 35". slabname's size should be 35 rather than 32.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52748.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
31083031709eea6530f0551d59eecdb2e68265ef
Fixed
c041f5ddef00c731c541e00bc8ae97b8c84c682f
Fixed
e4088d7d8f1123006d46a42edf51b8c960a58ef9
Fixed
526dd7540a09ecf87b5f54f3ab4e0a2528f25a79
Fixed
6fca08fd3085253b48fcb1bd243a0a5e18821a00
Fixed
3eebe636cac53886bd5d1cdd55e082ec9e84983f
Fixed
e0d4e8acb3789c5a8651061fbab62ca24a45c063

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.202
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.140
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.64
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.13
Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.3