Bug 2401544 (CVE-2023-53616)
| Summary: | CVE-2023-53616 kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A double-free vulnerability was found in the Linux kernel JFS filesystem's inode map cleanup. A local user with privileges to mount filesystems can mount a JFS filesystem, perform a remount operation that fails after freeing internal structures, then unmount the filesystem, causing the cleanup code to free the same memory twice, which results in memory corruption and denial of service through kernel crash.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-10-04 16:06:38 UTC
|