Wind River Support Network

HomeDefectsLIN1021-7643
Not to be fixed

LIN1021-7643 : Security Advisory - linux - CVE-2023-52526

Created: Mar 2, 2024    Updated: Apr 16, 2024
Resolved Date: Apr 16, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

erofs: fix memory leak of LZMA global compressed deduplication

When stressing microLZMA EROFS images with the new global compressed
deduplication feature enabled (`-Ededupe`), I found some short-lived
temporary pages weren't properly released, which could slowly cause
unexpected OOMs hours later.

Let's fix it now (LZ4 and DEFLATE don't have this issue.)

CREATE(Triage):(User=admin) CVE-2023-52526 (https://nvd.nist.gov/vuln/detail/CVE-2023-52526)
Live chat
Online