CVE-2023-54151

Source
https://cve.org/CVERecord?id=CVE-2023-54151
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54151.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-54151
Downstream
Published
2025-12-24T13:07:02.600Z
Modified
2026-04-02T09:45:38.325477Z
Summary
f2fs: Fix system crash due to lack of free space in LFS
Details

In the Linux kernel, the following vulnerability has been resolved:

f2fs: Fix system crash due to lack of free space in LFS

When f2fs tries to checkpoint during foreground gc in LFS mode, system crash occurs due to lack of free space if the amount of dirty node and dentry pages generated by data migration exceeds free space. The reproduction sequence is as follows.

  • 20GiB capacity block device (null_blk)
  • format and mount with LFS mode
  • create a file and write 20,000MiB
  • 4k random write on full range of the file

    RIP: 0010:newcurseg+0x48a/0x510 [f2fs] Code: 55 e7 f5 89 c0 48 0f af c3 48 8b 5d c0 48 c1 e8 20 83 c0 01 89 43 6c 48 83 c4 28 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc <0f> 0b f0 41 80 4f 48 04 45 85 f6 0f 84 ba fd ff ff e9 ef fe ff ff RSP: 0018:ffff977bc397b218 EFLAGS: 00010246 RAX: 00000000000027b9 RBX: 0000000000000000 RCX: 00000000000027c0 RDX: 0000000000000000 RSI: 00000000000027b9 RDI: ffff8c25ab4e74f8 RBP: ffff977bc397b268 R08: 00000000000027b9 R09: ffff8c29e4a34b40 R10: 0000000000000001 R11: ffff977bc397b0d8 R12: 0000000000000000 R13: ffff8c25b4dd81a0 R14: 0000000000000000 R15: ffff8c2f667f9000 FS: 0000000000000000(0000) GS:ffff8c344ec80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000c00055d000 CR3: 0000000e30810003 CR4: 00000000003706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> allocatesegmentbydefault+0x9c/0x110 [f2fs] f2fsallocatedata_block+0x243/0xa30 [f2fs] ? __modlruvecpagestate+0xa0/0x150 dowritepage+0x80/0x160 [f2fs] f2fsdowritenode_page+0x32/0x50 [f2fs] _writenodepage+0x339/0x730 [f2fs] f2fssyncnodepages+0x5a6/0x780 [f2fs] blockoperations+0x257/0x340 [f2fs] f2fswritecheckpoint+0x102/0x1050 [f2fs] f2fsgc+0x27c/0x630 [f2fs] ? foliomarkdirty+0x36/0x70 f2fsbalancefs+0x16f/0x180 [f2fs]

This patch adds checking whether free sections are enough before checkpoint during gc.

[Jaegeuk Kim: code clean-up]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54151.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a9163b947ae8f7af7cb8d63606cd87b9facbfe74
Fixed
f4631d295ae3fff9e240ab78dc17f4b83d14f7bc
Fixed
ce71c61d661cfac3f097af928995abfcebd2b8c5
Fixed
d11cef14f8146f3babd286c2cc8ca09c166295e2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
ec769406d06d5006c40554c4640f6e584ab6ae26
Last affected
8102416c05bb08795b9278a8664f9be827fadbe2
Last affected
938166b2b3051d9965c36f9b5228966d4f198b2a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54151.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.30
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54151.json"