CVE-2023-52458 is an input-validation flaw in the Linux kernel block layer's partition-addition and partition-resize handling. The affected code did not verify that a requested partition length was aligned to the target disk's logical block size. On devices whose logical block size exceeds 512 bytes, this permits creation or resizing of a partition whose size is not a multiple of that block size. A read of the partition's final sector can cause bio_truncate() to reduce the I/O below the logical block size. Where block integrity data is enabled, subsequent integrity cleanup can dereference a null pointer in bio_integrity_free.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel block-layer null-pointer dereference in ioctl handling when length and logical block size are misaligned.
Linux kernel block-layer null-pointer dereference caused by misaligned ioctl length and logical block size.
Linux kernel block-layer null-pointer dereference in ioctl handling when length and logical block size are misaligned.
Linux kernel block-layer null-pointer dereference triggered by misaligned length and logical block size values.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.