CVE-2023-53391 — Missing Release of Resource after Effective Lifetime in Linux
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
shmem: use ramfs_kill_sb() for kill_sb method of ramfs-based tmpfs
As the ramfs-based tmpfs uses ramfs_init_fs_context() for the
init_fs_context method, which allocates fc->s_fs_info, use ramfs_kill_sb()
to free it and avoid a memory leak.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
▶CVEListV5linux/linuxc3b1b1cbf002e65a3cabd479e68b5f35886a26db — 5fada375113767b3b57f1b04f7a4fe64ffaa626f+5
Patches
🔴Vulnerability Details
2OSV▶
CVE-2023-53391: In the Linux kernel, the following vulnerability has been resolved: shmem: use ramfs_kill_sb() for kill_sb method of ramfs-based tmpfs As the ramfs-ba↗2025-09-18
GHSA▶
GHSA-mxch-j2wj-hmc8: In the Linux kernel, the following vulnerability has been resolved:
shmem: use ramfs_kill_sb() for kill_sb method of ramfs-based tmpfs
As the ramfs-↗2025-09-18
📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2023-53391 kernel: Linux kernel: Memory leak in shmem's ramfs-based tmpfs leads to denial of service↗2025-09-18