CVE-2023-53796

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
09/12/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> f2fs: fix information leak in f2fs_move_inline_dirents()<br /> <br /> When converting an inline directory to a regular one, f2fs is leaking<br /> uninitialized memory to disk because it doesn&amp;#39;t initialize the entire<br /> directory block. Fix this by zero-initializing the block.<br /> <br /> This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded<br /> initializing when converting inline dentry"), which didn&amp;#39;t consider the<br /> security implications of leaking uninitialized memory to disk.<br /> <br /> This was found by running xfstest generic/435 on a KMSAN-enabled kernel.

Impact