{"id":"DEBIAN-CVE-2023-54153","details":"In the Linux kernel, the following vulnerability has been resolved:  ext4: turn quotas off if mount failed after enabling quotas  Yi found during a review of the patch \"ext4: don't BUG on inconsistent journal feature\" that when ext4_mark_recovery_complete() returns an error value, the error handling path does not turn off the enabled quotas, which triggers the following kmemleak:  ================================================================ unreferenced object 0xffff8cf68678e7c0 (size 64): comm \"mount\", pid 746, jiffies 4294871231 (age 11.540s) hex dump (first 32 bytes): 00 90 ef 82 f6 8c ff ff 00 00 00 00 41 01 00 00  ............A... c7 00 00 00 bd 00 00 00 0a 00 00 00 48 00 00 00  ............H... backtrace: [\u003c00000000c561ef24\u003e] __kmem_cache_alloc_node+0x4d4/0x880 [\u003c00000000d4e621d7\u003e] kmalloc_trace+0x39/0x140 [\u003c00000000837eee74\u003e] v2_read_file_info+0x18a/0x3a0 [\u003c0000000088f6c877\u003e] dquot_load_quota_sb+0x2ed/0x770 [\u003c00000000340a4782\u003e] dquot_load_quota_inode+0xc6/0x1c0 [\u003c0000000089a18bd5\u003e] ext4_enable_quotas+0x17e/0x3a0 [ext4] [\u003c000000003a0268fa\u003e] __ext4_fill_super+0x3448/0x3910 [ext4] [\u003c00000000b0f2a8a8\u003e] ext4_fill_super+0x13d/0x340 [ext4] [\u003c000000004a9489c4\u003e] get_tree_bdev+0x1dc/0x370 [\u003c000000006e723bf1\u003e] ext4_get_tree+0x1d/0x30 [ext4] [\u003c00000000c7cb663d\u003e] vfs_get_tree+0x31/0x160 [\u003c00000000320e1bed\u003e] do_new_mount+0x1d5/0x480 [\u003c00000000c074654c\u003e] path_mount+0x22e/0xbe0 [\u003c0000000003e97a8e\u003e] do_mount+0x95/0xc0 [\u003c000000002f3d3736\u003e] __x64_sys_mount+0xc4/0x160 [\u003c0000000027d2140c\u003e] do_syscall_64+0x3f/0x90 ================================================================  To solve this problem, we add a \"failed_mount10\" tag, and call ext4_quota_off_umount() in this tag to release the enabled qoutas.","modified":"2026-09-15T09:02:52.893825350Z","published":"2025-12-24T13:16:17.307Z","upstream":["CVE-2023-54153"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54153"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54153.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54153.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54153.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}