CVE-2023-53796
published 2025-12-09CVE-2023-53796: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline…
PriorityP421
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inline directory to a regular one, f2fs is leaking
uninitialized memory to disk because it doesn't initialize the entire
directory block. Fix this by zero-initializing the block.
This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded
initializing when converting inline dentry"), which didn't consider the
security implications of leaking uninitialized memory to disk.
This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < 4e3b4b170bd43db1d8a93a6bd0ea434b17cc86f7 | 4e3b4b170bd43db1d8a93a6bd0ea434b17cc86f7 |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < a6807ef0f3b3d8508d3b07a2e35de8a91820a014 | a6807ef0f3b3d8508d3b07a2e35de8a91820a014 |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < 2bef8314fcf94ddc27e22d03f237c0fafd00de33 | 2bef8314fcf94ddc27e22d03f237c0fafd00de33 |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < 00b5587326625d0fddb2a5f5a3d4acd950102ace | 00b5587326625d0fddb2a5f5a3d4acd950102ace |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < 117d4f6687b1f74423b5d398ea95c63b262a8e73 | 117d4f6687b1f74423b5d398ea95c63b262a8e73 |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < f07a8d61b6ea81bb3cbe0638af40f8824d6147fd | f07a8d61b6ea81bb3cbe0638af40f8824d6147fd |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < eebaecef0095bb8f493c03982da75c6e7bae1056 | eebaecef0095bb8f493c03982da75c6e7bae1056 |
| linux | linux | >= 4ec17d688d74b6b7cb10043c57ff4818cde2b0ca < 9a5571cff4ffcfc24847df9fd545cc5799ac0ee5 | 9a5571cff4ffcfc24847df9fd545cc5799ac0ee5 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 4.15.0 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.20.0 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 4.3.0 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 5.11.0 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.5.0 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2.0 < 6.2.3 | 6.2.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: f2fs: fix information leak in f2fs_move_inline_dirents()
vendor_redhat·2025-12-09
CVE-2023-53796 kernel: f2fs: fix information leak in f2fs_move_inline_dirents()
kernel: f2fs: fix information leak in f2fs_move_inline_dirents()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inline directory to a regular one, f2fs is leaking
uninitialized memory to disk because it doesn't initialize the entire
directory block. Fix this by zero-initializing the block.
This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded
initializing when converting inline dentry"), which didn't consider the
security implications of leaking uninitialized memory to disk.
This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package:
Debian
CVE-2023-53796: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix i...
vendor_debian·2023
CVE-2023-53796 CVE-2023-53796: linux - In the Linux kernel, the following vulnerability has been resolved: f2fs: fix i...
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline directory to a regular one, f2fs is leaking uninitialized memory to disk because it doesn't initialize the entire directory block. Fix this by zero-initializing the block. This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded initializing when converting inline dentry"), which didn't consider the security implications of leaking uninitialized memory to disk. This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
GHSA
GHSA-g2pf-697j-2r49: In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inli
ghsa_unreviewed·2025-12-09
CVE-2023-53796 GHSA-g2pf-697j-2r49: In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inli
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inline directory to a regular one, f2fs is leaking
uninitialized memory to disk because it doesn't initialize the entire
directory block. Fix this by zero-initializing the block.
This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded
initializing when converting inline dentry"), which didn't consider the
security implications of leaking uninitialized memory to disk.
This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
OSV
f2fs: fix information leak in f2fs_move_inline_dirents()
osv·2025-12-09
CVE-2023-53796 f2fs: fix information leak in f2fs_move_inline_dirents()
f2fs: fix information leak in f2fs_move_inline_dirents()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix information leak in f2fs_move_inline_dirents()
When converting an inline directory to a regular one, f2fs is leaking
uninitialized memory to disk because it doesn't initialize the entire
directory block. Fix this by zero-initializing the block.
This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded
initializing when converting inline dentry"), which didn't consider the
security implications of leaking uninitialized memory to disk.
This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
OSV
CVE-2023-53796: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline
osv·2025-12-09
CVE-2023-53796 CVE-2023-53796: In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline directory to a regular one, f2fs is leaking uninitialized memory to disk because it doesn't initialize the entire directory block. Fix this by zero-initializing the block. This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded initializing when converting inline dentry"), which didn't consider the security implications of leaking uninitialized memory to disk. This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/00b5587326625d0fddb2a5f5a3d4acd950102acehttps://git.kernel.org/stable/c/117d4f6687b1f74423b5d398ea95c63b262a8e73https://git.kernel.org/stable/c/2bef8314fcf94ddc27e22d03f237c0fafd00de33https://git.kernel.org/stable/c/4e3b4b170bd43db1d8a93a6bd0ea434b17cc86f7https://git.kernel.org/stable/c/9a5571cff4ffcfc24847df9fd545cc5799ac0ee5https://git.kernel.org/stable/c/a6807ef0f3b3d8508d3b07a2e35de8a91820a014https://git.kernel.org/stable/c/eebaecef0095bb8f493c03982da75c6e7bae1056https://git.kernel.org/stable/c/f07a8d61b6ea81bb3cbe0638af40f8824d6147fd
2025-12-09
Published