{"id":"DEBIAN-CVE-2023-53035","details":"In the Linux kernel, the following vulnerability has been resolved:  nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_copy()  The ioctl helper function nilfs_ioctl_wrap_copy(), which exchanges a metadata array to/from user space, may copy uninitialized buffer regions to user space memory for read-only ioctl commands NILFS_IOCTL_GET_SUINFO and NILFS_IOCTL_GET_CPINFO.  This can occur when the element size of the user space metadata given by the v_size member of the argument nilfs_argv structure is larger than the size of the metadata element (nilfs_suinfo structure or nilfs_cpinfo structure) on the file system side.  KMSAN-enabled kernels detect this issue as follows:   BUG: KMSAN: kernel-infoleak in instrument_copy_to_user  include/linux/instrumented.h:121 [inline]  BUG: KMSAN: kernel-infoleak in _copy_to_user+0xc0/0x100 lib/usercopy.c:33   instrument_copy_to_user include/linux/instrumented.h:121 [inline]   _copy_to_user+0xc0/0x100 lib/usercopy.c:33   copy_to_user include/linux/uaccess.h:169 [inline]   nilfs_ioctl_wrap_copy+0x6fa/0xc10 fs/nilfs2/ioctl.c:99   nilfs_ioctl_get_info fs/nilfs2/ioctl.c:1173 [inline]   nilfs_ioctl+0x2402/0x4450 fs/nilfs2/ioctl.c:1290   nilfs_compat_ioctl+0x1b8/0x200 fs/nilfs2/ioctl.c:1343   __do_compat_sys_ioctl fs/ioctl.c:968 [inline]   __se_compat_sys_ioctl+0x7dd/0x1000 fs/ioctl.c:910   __ia32_compat_sys_ioctl+0x93/0xd0 fs/ioctl.c:910   do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline]   __do_fast_syscall_32+0xa2/0x100 arch/x86/entry/common.c:178   do_fast_syscall_32+0x37/0x80 arch/x86/entry/common.c:203   do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:246   entry_SYSENTER_compat_after_hwframe+0x70/0x82   Uninit was created at:   __alloc_pages+0x9f6/0xe90 mm/page_alloc.c:5572   alloc_pages+0xab0/0xd80 mm/mempolicy.c:2287   __get_free_pages+0x34/0xc0 mm/page_alloc.c:5599   nilfs_ioctl_wrap_copy+0x223/0xc10 fs/nilfs2/ioctl.c:74   nilfs_ioctl_get_info fs/nilfs2/ioctl.c:1173 [inline]   nilfs_ioctl+0x2402/0x4450 fs/nilfs2/ioctl.c:1290   nilfs_compat_ioctl+0x1b8/0x200 fs/nilfs2/ioctl.c:1343   __do_compat_sys_ioctl fs/ioctl.c:968 [inline]   __se_compat_sys_ioctl+0x7dd/0x1000 fs/ioctl.c:910   __ia32_compat_sys_ioctl+0x93/0xd0 fs/ioctl.c:910   do_syscall_32_irqs_on arch/x86/entry/common.c:112 [inline]   __do_fast_syscall_32+0xa2/0x100 arch/x86/entry/common.c:178   do_fast_syscall_32+0x37/0x80 arch/x86/entry/common.c:203   do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:246   entry_SYSENTER_compat_after_hwframe+0x70/0x82   Bytes 16-127 of 3968 are uninitialized  ...  This eliminates the leak issue by initializing the page allocated as buffer using get_zeroed_page().","modified":"2026-09-15T09:02:50.230835100Z","published":"2025-05-02T16:15:22.627Z","upstream":["CVE-2023-53035"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53035"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53035.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53035.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53035.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}