CVE-2023-53396Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in do_rename If renaming a file in an encrypted directory, function fscrypt_setup_filename allocates memory for a file name. This name is never used, and before returning to the caller the memory for it is not freed. When running kmemleak on it we see that it is registered as a leak. The report below is triggered by a simple program 'rename' that renames a file in an encrypted directory: unreferenced o

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.15.335.15.112+4
Debianlinux/linux_kernel< 6.1.37-1+2
CVEListV5linux/linuxc67bc98d1f0853bb196e9c48eab38b6f2ddab79543b2f7d690697182beed6f71aa57b7249d3cfc9c+7
debiandebian/linux< linux 6.1.37-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53396: In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in do_rename If renaming a file in an encrypted directory,2025-09-18
GHSA
GHSA-427x-59vx-vjwq: In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in do_rename If renaming a file in an encrypted directory2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Memory leak leading to denial of service via renaming a file in an encrypted directory2025-09-18
Debian
CVE-2023-53396: linux - In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix ...2023

💬Community

1
Bugzilla
CVE-2023-53396 kernel: Linux kernel: Memory leak leading to denial of service via renaming a file in an encrypted directory2025-09-18
CVE-2023-53396 — Linux vulnerability | cvebase