The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
https://www.spinics.net/lists/stable-commits/msg317086.html
https://lore.kernel.org/lkml/aa03f191-445c-0d2e-d6d7-0a3208d7df7a%40huawei.com/T/
https://www.cisa.gov/news-events/ics-advisories/icsa-24-102-01
https://cert-portal.siemens.com/productcert/html/ssa-265688.html
https://lkml.org/lkml/2023/8/13/477
https://github.com/torvalds/linux/commit/768d612f79822d30a1e7d132a4d4b05337ce42ec
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.4
Source: Mitre, NVD
Published: 2023-10-16
Updated: 2024-08-26
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00106