CVE-2023-53278

MEDIUM

Linux kernel 5.17-6.1.17, 6.2.0-6.2.4 - Use-After-Free in UBIFS Sysfs Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in ubifs_sysfs_init() When insmod ubifs.ko, a kmemleak reported as below: unreferenced object 0xffff88817fb1a780 (size 8): comm "insmod", pid 25265, jiffies 4295239702 (age 100.130s) hex dump (first 8 bytes): 75 62 69 66 73 00 ff ff ubifs... backtrace: [<ffffffff81b3fc4c>] slab_post_alloc_hook+0x9c/0x3c0 [<ffffffff81b44bf3>] __kmalloc_track_caller+0x183/0x410 [<ffffffff8198d3da>] kstrdup+0x3a/0x80 [<ffffffff8198d486>] kstrdup_const+0x66/0x80 [<ffffffff83989325>] kvasprintf_const+0x155/0x190 [<ffffffff83bf55bb>] kobject_set_name_vargs+0x5b/0x150 [<ffffffff83bf576b>] kobject_set_name+0xbb/0xf0 [<ffffffff8100204c>] do_one_initcall+0x14c/0x5a0 [<ffffffff8157e380>] do_init_module+0x1f0/0x660 [<ffffffff815857be>] load_module+0x6d7e/0x7590 [<ffffffff8158644f>] __do_sys_finit_module+0x19f/0x230 [<ffffffff815866b3>] __x64_sys_finit_module+0x73/0xb0 [<ffffffff88c98e85>] do_syscall_64+0x35/0x80 [<ffffffff88e00087>] entry_SYSCALL_64_after_hwframe+0x63/0xcd When kset_register() failed, we should call kset_put to cleanup it.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (9)
Linux/Linux < 5.17
Linux/Linux 2e3cbf425804fb44a005e252f88f93dff108c911 - 1c5fdf2d4647219d2267ccb08c7f2c7095bf3450
Linux/Linux 2e3cbf425804fb44a005e252f88f93dff108c911 - 203a55f04f66eea1a1ca7e5a302a7f5c99c62327
Linux/Linux 2e3cbf425804fb44a005e252f88f93dff108c911 - d42c2b18c42da7378e67b6414aafe93b65de89d1
Linux/Linux 5.17
Linux/Linux 6.1.18 - 6.1.*
Linux/Linux 6.2.5 - 6.2.*
Linux/Linux 6.3
linux/linux_kernel 5.17 - 6.1.18
Published Sep 16, 2025
Tracked Since Feb 18, 2026