Executive brief
The Linux kernel's JFS (Journaled File System) contains a memory management flaw in its remount logic. When a remount operation fails, the cleanup code attempts to free memory blocks that have already been freed, potentially allowing an attacker to crash the system or gain control of kernel memory. This affects systems using JFS filesystems.
Technical details
The vulnerability is a double-free bug in the JFS filesystem driver (fs/jfs/jfs_dmap.c:264). When jfs_remount() invokes either diMount() or dbMount() and these operations fail, the corresponding cleanup functions (diUnmount() or dbUnmount()) have already executed during the failed mount attempt. On subsequent unmount or remount operations, these cleanup functions are called again, attempting to free memory that was already deallocated, triggering a kernel panic detected by KASAN. The root cause is that JFS_SBI(ipbmap->i_sb)->bmap is not set to NULL after kfree() in dbUnmount(), leaving a dangling pointer. The vulnerability is reachable by any user able to remount a JFS filesystem with filesystem configuration operations (fsconfig syscall), requiring no special privileges on local systems.
Affected products
- Linux Linux kernel before patch (CVE-2023-54127)
Timeline
- 2025-12-24: disclosed