Home

Description

In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths When processing mount options, efivarfs allocates efivarfs_fs_info (sfi) early in fs_context initialization. However, sfi is associated with the superblock and typically freed when the superblock is destroyed. If the fs_context is released (final put) before fill_super is called—such as on error paths or during reconfiguration—the sfi structure would leak, as ownership never transfers to the superblock. Implement the .free callback in efivarfs_context_ops to ensure any allocated sfi is properly freed if the fs_context is torn down before fill_super, preventing this memory leak.

PUBLISHED Reserved 2025-04-16 | Published 2025-08-16 | Updated 2025-08-16 | Assigner Linux

Product status

Default status
unaffected

5329aa5101f73c451bcd48deaf3f296685849d9c before 816d36973467d1c9c08a48bdffe4675e219a2e84
affected

5329aa5101f73c451bcd48deaf3f296685849d9c before e9fabe7036bb8be6071f39dc38605508f5f57b20
affected

5329aa5101f73c451bcd48deaf3f296685849d9c before 64e135f1eaba0bbb0cdee859af3328c68d5b9789
affected

Default status
affected

6.7
affected

Any version before 6.7
unaffected

6.12.40
unaffected

6.15.8
unaffected

6.16
unaffected

References

git.kernel.org/...c/816d36973467d1c9c08a48bdffe4675e219a2e84

git.kernel.org/...c/e9fabe7036bb8be6071f39dc38605508f5f57b20

git.kernel.org/...c/64e135f1eaba0bbb0cdee859af3328c68d5b9789

cve.org (CVE-2025-38549)

nvd.nist.gov (CVE-2025-38549)

Download JSON