CVE-2023-53796

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix information leak in f2fs_move_inline_dirents() When converting an inline directory to a regular one, f2fs is leaking uninitialized memory to disk because it doesn't initialize the entire directory block. Fix this by zero-initializing the block. This bug was introduced by commit 4ec17d688d74 ("f2fs: avoid unneeded initializing when converting inline dentry"), which didn't consider the security implications of leaking uninitialized memory to disk. This was found by running xfstest generic/435 on a KMSAN-enabled kernel.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-12-09 01:16

Updated : 2026-06-17 06:46


NVD link : CVE-2023-53796

Mitre link : CVE-2023-53796

CVE.ORG link : CVE-2023-53796


JSON object : View

Products Affected

No product.

CWE

No CWE.