SB2025123078 - Memory leak in Linux kernel btrfs
Published: December 30, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-54297)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the exclude_super_stripes() function in fs/btrfs/block-group.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/ab80a901f8daca07c4a54af0ab0de745c9918294
- https://git.kernel.org/stable/c/c35ea606196243063e63785918c7c8fe27c45798
- https://git.kernel.org/stable/c/cca627afb463a4b47721eac017516ba200de85c3
- https://git.kernel.org/stable/c/f1a07c2b4e2c473ec322b8b9ece071b8c88a3512
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.123
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5