CVE-2023-52622 is an ext4 filesystem vulnerability that can prevent online resizing of filesystems created with an oversized flexible block-group (flex_bg) configuration. During resizing, ext4 may attempt to allocate a new_group_data array larger than the kernel allocator's MAX_ORDER limit, triggering a WARN_ON condition and causing the resize operation to fail. Red Hat rates the issue CVSS 3.1 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H): a local low-privileged user can cause a high availability impact without user interaction.
Upstream Linux fixed the issue by limiting each resize pass to MAX_RESIZE_BG—16,384 block groups—and completing larger expansions over multiple iterations, potentially dispersing metadata within a flex_bg. Fixes are available in stable kernels 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8. Red Hat released fixes for affected RHEL 8 and RHEL 9 kernel packages through errata issued from August 2024 to May 2025; RHEL 9 kernel-rt remains affected, while RHEL 6 and 7 are outside support scope.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 for the RHEL 8 kernel and RHSA-2024:5102 for the RHEL 8 kernel-rt, addressing CVE-2023-52622.
Red Hat released RHSA-2025:8248 to address CVE-2023-52622 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315, fixing CVE-2023-52622 in the Red Hat Enterprise Linux 9 kernel.
Stable kernel releases 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8 incorporated a fix that caps each ext4 resize iteration at 16,384 groups and handles larger expansions in multiple iterations.
The Linux kernel CVE team assigned CVE-2023-52622 for an ext4 issue where an oversized flex_bg configuration can make an online resize allocate beyond the kernel allocator's MAX_ORDER limit, causing a warning and resize failure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.