cbcvebase.
CVE-2023-52670
published 2024-05-17

CVE-2023-52670: In the Linux kernel, the following vulnerability has been resolved: rpmsg: virtio: Free driver_override when rpmsg_remove() Free driver_override when…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
20.7th percentile
In the Linux kernel, the following vulnerability has been resolved: rpmsg: virtio: Free driver_override when rpmsg_remove() Free driver_override when rpmsg_remove(), otherwise the following memory leak will occur: unreferenced object 0xffff0000d55d7080 (size 128): comm "kworker/u8:2", pid 56, jiffies 4294893188 (age 214.272s) hex dump (first 32 bytes): 72 70 6d 73 67 5f 6e 73 00 00 00 00 00 00 00 00 rpmsg_ns........ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmem_cache_alloc_node+0x1f8/0x320 [] __kmalloc_node_track_caller+0x44/0x70 [] kstrndup+0x4c/0x90 [] driver_set_override+0xd0/0x164 [] rpmsg_register_device_override+0x98/0x170 [] rpmsg_ns_register_device+0x24/0x30 [] rpmsg_probe+0x2e0/0x3ec [] virtio_dev_probe+0x1c0/0x280 [] really_probe+0xbc/0x2dc [] __driver_probe_device+0x78/0xe0 [] driver_probe_device+0xd8/0x160 [] __device_attach_driver+0xb8/0x140 [] bus_for_each_drv+0x7c/0xd4 [] __device_attach+0x9c/0x19c [] device_initial_probe+0x14/0x20 [] bus_probe_device+0xa0/0xac

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < 229ce47cbfdc7d3a9415eb676abbfb77d676cb08229ce47cbfdc7d3a9415eb676abbfb77d676cb08
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < dd50fe18c234bd5ff22f658f4d414e8fa8cd6a5ddd50fe18c234bd5ff22f658f4d414e8fa8cd6a5d
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < 69ca89d80f2c8a1f5af429b955637beea7eead3069ca89d80f2c8a1f5af429b955637beea7eead30
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < 2d27a7b19cb354c6d04bcdc9239e261ff29858d62d27a7b19cb354c6d04bcdc9239e261ff29858d6
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < f4bb1d5daf77b1a95a43277268adf0d1430c2346f4bb1d5daf77b1a95a43277268adf0d1430c2346
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < 4e6cef3fae5c164968118a13f3fe293700adc81a4e6cef3fae5c164968118a13f3fe293700adc81a
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < 9a416d624e5fb7246ea97c11fbfea7e0e27abf439a416d624e5fb7246ea97c11fbfea7e0e27abf43
linuxlinux>= b0b03b8119633de0649da9bd506e4850c401ff2b < d5362c37e1f8a40096452fc201c30e705750e687d5362c37e1f8a40096452fc201c30e705750e687
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 4.13 < 4.19.3074.19.307
linuxlinux_kernel>= 4.20 < 5.4.2695.4.269
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76
linuxlinux_kernel>= 5.5 < 5.10.2105.10.210
linuxlinux_kernel>= 6.2 < 6.6.156.6.15
linuxlinux_kernel>= 6.7 < 6.7.36.7.3
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_msrc6.6MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.