Junglewise Threat Intelligence

CVE-2023-54153: Linux kernel ext4 quota disable failure in mount error handling

CVE-2023-54153 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The ext4 filesystem driver in the Linux kernel fails to properly disable quotas when a mount operation encounters an error after quotas have been enabled. This creates a memory leak and leaves the system in an inconsistent state. An attacker or user could trigger this condition repeatedly to exhaust memory or cause denial of service, particularly on systems that use ext4 quotas for resource management.

Technical details

The vulnerability is a resource cleanup failure in ext4 mount error handling. When ext4_mark_recovery_complete() fails during the mount process (which occurs after ext4_enable_quotas() has already been called), the error path does not invoke the proper quota shutdown routine. This leaves quota data structures allocated in kernel memory with no proper cleanup path, resulting in a kernel memory leak. The issue affects systems with ext4 quotas enabled; exploitation does not require special privileges but can be triggered by repeated failed mount attempts. A patch adds proper quota cleanup in the failed_mount10 error path by calling ext4_quota_off_umount().

Affected products

  • Linux Linux kernel affected versions unknown

Timeline

  • 2025-12-24: disclosed: CVE-2023-54153 published

Related threats