-
CVE-2023-53796
- EPSS 0.03%
- Veröffentlicht 09.12.2025 00:00:52
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
f2fs: fix information leak in f2fs_move_inline_dirents()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inline directory to a regular one, f2fs is leaking
uninitialized memory to disk because it doesn't initialize the entire
directory block. Fix this by zero-initializing the block.
This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded
initializing when converting inline dentry"), which didn't consider the
security implications of leaking uninitialized memory to disk.
This was found by running xfstest generic/435 on a KMSAN-enabled kernel.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
4e3b4b170bd43db1d8a93a6bd0ea434b17cc86f7
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
a6807ef0f3b3d8508d3b07a2e35de8a91820a014
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
2bef8314fcf94ddc27e22d03f237c0fafd00de33
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
00b5587326625d0fddb2a5f5a3d4acd950102ace
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
117d4f6687b1f74423b5d398ea95c63b262a8e73
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
f07a8d61b6ea81bb3cbe0638af40f8824d6147fd
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
eebaecef0095bb8f493c03982da75c6e7bae1056
Status
affected
Version
4ec17d688d74b6b7cb10043c57ff4818cde2b0ca
Version <
9a5571cff4ffcfc24847df9fd545cc5799ac0ee5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.3
Status
affected
Version
0
Version <
4.3
Status
unaffected
Version <=
4.14.*
Version
4.14.308
Status
unaffected
Version <=
4.19.*
Version
4.19.276
Status
unaffected
Version <=
5.4.*
Version
5.4.235
Status
unaffected
Version <=
5.10.*
Version
5.10.173
Status
unaffected
Version <=
5.15.*
Version
5.15.99
Status
unaffected
Version <=
6.1.*
Version
6.1.16
Status
unaffected
Version <=
6.2.*
Version
6.2.3
Status
unaffected
Version <=
*
Version
6.3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|