{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-52731",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-05-21T15:19:24.232Z",
        "datePublished": "2024-05-21T15:22:57.282Z",
        "dateUpdated": "2026-08-05T09:11:07.269Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:11:07.269Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Fix invalid page access after closing deferred I/O devices\n\nWhen a fbdev with deferred I/O is once opened and closed, the dirty\npages still remain queued in the pageref list, and eventually later\nthose may be processed in the delayed work.  This may lead to a\ncorruption of pages, hitting an Oops.\n\nThis patch makes sure to cancel the delayed work and clean up the\npageref list at closing the device for addressing the bug.  A part of\nthe cleanup code is factored out as a new helper function that is\ncalled from the common fb_release()."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Exploitation requires opening, mmaping, writing, and closing a local framebuffer device node (/dev/fb*), which is a local syscall/device-file attack path rather than network or adjacent-network access.\nAC:L - The attacker fully controls the trigger sequence (mmap write to queue dirty pagerefs and schedule delayed work, then close before the work runs); the deferred-I/O delay is deterministic and requires no conditions outside attacker control.\nPR:L - fb_open/fb_mmap impose no capability checks; access is gated only by /dev/fb* permissions (typically root:video), so an unprivileged video-group or similarly permitted local user can reach the bug without real root.\nUI:N - The attacker performs open/mmap/write/close themselves; no separate victim action is required to trigger the deferred work on the stale pageref list.\nS:U - Impact is confined to the host kernel authority (local privilege escalation / crash); this is not a VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Closing leaves dirty pagerefs queued and page->mapping set on framebuffer pages, so later deferred work performs invalid page access and page corruption; such kernel memory corruption can be leveraged for information disclosure.\nI:H - The same stale-pageref / unclean page->mapping path corrupts kernel page state and can be abused for integrity violation or control-flow hijacking, consistent with treating this class of memory corruption as high integrity impact.\nA:H - The commit explicitly documents that processing the leftover pagerefs after close leads to an Oops/kernel crash, which is high availability impact."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/core/fb_defio.c",
                        "drivers/video/fbdev/core/fbmem.c",
                        "include/linux/fb.h"
                    ],
                    "versions": [
                        {
                            "version": "186b89659c4c67cccead52961eab0ca3b23951dc",
                            "lessThan": "87b9802ca824fcee7915e717e9a60471af62e8e9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "56c134f7f1b58be08bdb0ca8372474a4a5165f31",
                            "lessThan": "f1d91f0e9d5a240a809698d7d9c5a538e7dcc149",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "56c134f7f1b58be08bdb0ca8372474a4a5165f31",
                            "lessThan": "3efc61d95259956db25347e2a9562c3e54546e20",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/video/fbdev/core/fb_defio.c",
                        "drivers/video/fbdev/core/fbmem.c",
                        "include/linux/fb.h"
                    ],
                    "versions": [
                        {
                            "version": "5.19",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.19",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.13",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.1.13"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.19",
                                    "versionEndExcluding": "6.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/87b9802ca824fcee7915e717e9a60471af62e8e9"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f1d91f0e9d5a240a809698d7d9c5a538e7dcc149"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3efc61d95259956db25347e2a9562c3e54546e20"
                }
            ],
            "title": "fbdev: Fix invalid page access after closing deferred I/O devices",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2024-08-02T23:11:35.499Z"
                },
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://git.kernel.org/stable/c/87b9802ca824fcee7915e717e9a60471af62e8e9",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/f1d91f0e9d5a240a809698d7d9c5a538e7dcc149",
                        "tags": [
                            "x_transferred"
                        ]
                    },
                    {
                        "url": "https://git.kernel.org/stable/c/3efc61d95259956db25347e2a9562c3e54546e20",
                        "tags": [
                            "x_transferred"
                        ]
                    }
                ]
            },
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2023-52731",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-09-10T15:37:38.155499Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-11T17:33:36.311Z"
                }
            }
        ]
    }
}