{"id":"DEBIAN-CVE-2023-54194","details":"In the Linux kernel, the following vulnerability has been resolved:  exfat: use kvmalloc_array/kvfree instead of kmalloc_array/kfree  The call stack shown below is a scenario in the Linux 4.19 kernel. Allocating memory failed where exfat fs use kmalloc_array due to system memory fragmentation, while the u-disk was inserted without recognition. Devices such as u-disk using the exfat file system are pluggable and may be insert into the system at any time. However, long-term running systems cannot guarantee the continuity of physical memory. Therefore, it's necessary to address this issue.  Binder:2632_6: page allocation failure: order:4,  mode:0x6040c0(GFP_KERNEL|__GFP_COMP), nodemask=(null) Call trace: [242178.097582]  dump_backtrace+0x0/0x4 [242178.097589]  dump_stack+0xf4/0x134 [242178.097598]  warn_alloc+0xd8/0x144 [242178.097603]  __alloc_pages_nodemask+0x1364/0x1384 [242178.097608]  kmalloc_order+0x2c/0x510 [242178.097612]  kmalloc_order_trace+0x40/0x16c [242178.097618]  __kmalloc+0x360/0x408 [242178.097624]  load_alloc_bitmap+0x160/0x284 [242178.097628]  exfat_fill_super+0xa3c/0xe7c [242178.097635]  mount_bdev+0x2e8/0x3a0 [242178.097638]  exfat_fs_mount+0x40/0x50 [242178.097643]  mount_fs+0x138/0x2e8 [242178.097649]  vfs_kern_mount+0x90/0x270 [242178.097655]  do_mount+0x798/0x173c [242178.097659]  ksys_mount+0x114/0x1ac [242178.097665]  __arm64_sys_mount+0x24/0x34 [242178.097671]  el0_svc_common+0xb8/0x1b8 [242178.097676]  el0_svc_handler+0x74/0x90 [242178.097681]  el0_svc+0x8/0x340  By analyzing the exfat code,we found that continuous physical memory is not required here,so kvmalloc_array is used can solve this problem.","modified":"2026-09-15T08:47:48.081524108Z","published":"2025-12-30T13:16:07.437Z","upstream":["CVE-2023-54194"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54194"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54194.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54194.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54194.json"}}],"schema_version":"1.9.0"}