{"id":"CVE-2023-53276","summary":"ubifs: Free memory for tmpfile name","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: Free memory for tmpfile name\n\nWhen opening a ubifs tmpfile on an encrypted directory, function\nfscrypt_setup_filename allocates memory for the name that is to be\nstored in the directory entry, but after the name has been copied to the\ndirectory entry inode, the memory is not freed.\n\nWhen running kmemleak on it we see that it is registered as a leak. The\nreport below is triggered by a simple program 'tmpfile' just opening a\ntmpfile:\n\n  unreferenced object 0xffff88810178f380 (size 32):\n    comm \"tmpfile\", pid 509, jiffies 4294934744 (age 1524.742s)\n    backtrace:\n      __kmem_cache_alloc_node\n      __kmalloc\n      fscrypt_setup_filename\n      ubifs_tmpfile\n      vfs_tmpfile\n      path_openat\n\nFree this memory after it has been copied to the inode.","modified":"2026-04-11T12:46:44.126747Z","published":"2025-09-16T08:11:11.328Z","related":["SUSE-SU-2025:03615-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3761-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53276.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/107d481642c356a5668058066360fc473911e628"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1e43d4284bdc3bd34bd770fea13910ac37ab0618"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1fb815b38bb31d6af9bd0540b8652a0d6fe6cfd3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/29738e1bcc799dd754711d4e4aab967f0c018175"},{"type":"WEB","url":"https://git.kernel.org/stable/c/823f554747f8aafaa965fb2f3ae794110ed429ef"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8ad8c67a897e68426e85990ebfe0a7d1f71fc79f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b8f444a4fadfb5070ed7e298e0a5ceb4a18014f3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ce840284929b75dbbf062e0ce7fcb78a63b08b5e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fd197308c0e4f738c7ea687d5332035c5753881c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53276.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53276"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f4f61d2cc6d8789a52245a4733b3e5643be154f3"},{"fixed":"8ad8c67a897e68426e85990ebfe0a7d1f71fc79f"},{"fixed":"107d481642c356a5668058066360fc473911e628"},{"fixed":"823f554747f8aafaa965fb2f3ae794110ed429ef"},{"fixed":"b8f444a4fadfb5070ed7e298e0a5ceb4a18014f3"},{"fixed":"ce840284929b75dbbf062e0ce7fcb78a63b08b5e"},{"fixed":"29738e1bcc799dd754711d4e4aab967f0c018175"},{"fixed":"fd197308c0e4f738c7ea687d5332035c5753881c"},{"fixed":"1e43d4284bdc3bd34bd770fea13910ac37ab0618"},{"fixed":"1fb815b38bb31d6af9bd0540b8652a0d6fe6cfd3"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53276.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"4.14.315"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.15.0"},{"fixed":"4.19.283"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.243"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.180"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.111"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.28"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.15"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"fixed":"6.3.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53276.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}