PT-2025-53154 · Linux+1 · Linux Kernel+1

Published

2023-03-27

·

Updated

2025-12-25

·

CVE-2023-54077

CVSS v2.0

4.3

Medium

VectorAV:A/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a memory leak in the ntfs3 filesystem when the ntfs read mft function fails under specific conditions. The issue arises from inconsistencies in setting flags related to directory attributes during the processing of MFT (Master File Table) entries. Specifically, the ATTR ROOT label sets is root to true and NI FLAG DIR, but these states are not always consistent. This can lead to a memory leak because the cleanup function ni clear() frees the wrong memory allocation (ni->file.run instead of ni->dir.alloc run) when NI FLAG DIR is not set. The backtrace indicates the leak occurs during the allocation of memory for directory entries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2026-01135
CVE-2023-54077

Affected Products

Linux Kernel
Ntfs3