Junglewise Threat Intelligence

CVE-2023-54127: Linux kernel JFS double-free in dbUnmount after failed remount

CVE-2023-54127 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's JFS (Journaled File System) contains a memory management flaw in its remount logic. When a remount operation fails, the cleanup code attempts to free memory blocks that have already been freed, potentially allowing an attacker to crash the system or gain control of kernel memory. This affects systems using JFS filesystems.

Technical details

The vulnerability is a double-free bug in the JFS filesystem driver (fs/jfs/jfs_dmap.c:264). When jfs_remount() invokes either diMount() or dbMount() and these operations fail, the corresponding cleanup functions (diUnmount() or dbUnmount()) have already executed during the failed mount attempt. On subsequent unmount or remount operations, these cleanup functions are called again, attempting to free memory that was already deallocated, triggering a kernel panic detected by KASAN. The root cause is that JFS_SBI(ipbmap->i_sb)->bmap is not set to NULL after kfree() in dbUnmount(), leaving a dangling pointer. The vulnerability is reachable by any user able to remount a JFS filesystem with filesystem configuration operations (fsconfig syscall), requiring no special privileges on local systems.

Affected products

  • Linux Linux kernel before patch (CVE-2023-54127)

Timeline

  • 2025-12-24: disclosed

Related threats