Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} If the filename casefolding fails, we'll be leaking memory from the fscrypt_name struct, namely from the 'crypto_buf.name' member. Make sure we free it in the error path on both ext4_fname_setup_filename() and ext4_fname_prepare_lookup() functions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.13, < 6.1.54 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/1fb3f1bbfdb511034b0360dbeb0f6a8424ed2a5cPatch
- https://git.kernel.org/stable/c/36daf050be3f6f067631dc52054de2d3b7cc849fPatch
- https://git.kernel.org/stable/c/7ca4b085f430f3774c3838b3da569ceccd6a0177Patch
- https://git.kernel.org/stable/c/98fc9c2cc45cfcb56961a73de3ec69b474063fc0
FAQ
What is CVE-2023-53662?
CVE-2023-53662 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} If the filename casefolding fails, we'll be leaking memory fr...
How severe is CVE-2023-53662?
CVE-2023-53662 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53662?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.