SB2025122615 - Memory leak in Linux kernel ext4
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-54153)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the __ext4_fill_super() function in fs/ext4/super.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/77c3ca1108eb4a26db4f256c42b271a430cebc7d
- https://git.kernel.org/stable/c/c327b83c59ee938792a0300df646efac39c7d6a7
- https://git.kernel.org/stable/c/d13f99632748462c32fc95d729f5e754bab06064
- https://git.kernel.org/stable/c/deef86fa3005cbb61ae8aa5729324c09b3f4ba73
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.40