CVE-2023-52902
published 2024-08-21CVE-2023-52902: In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree nodes…
PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tree nodes may leak if the error path to
"error_just_free" is taken. Fix this by moving the freeing of the maple
tree nodes to a shared location for all error paths.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.8-1 (bookworm) | linux 6.1.8-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 8220543df1489ef96c3d4e8b0b3b03c340e3943e < 1442d51026c58e7c11dd5f9b19650632a48676d4 | 1442d51026c58e7c11dd5f9b19650632a48676d4 |
| linux | linux | >= 8220543df1489ef96c3d4e8b0b3b03c340e3943e < 7f31cced5724e6d414fe750aa1cd7e7b578ec22f | 7f31cced5724e6d414fe750aa1cd7e7b578ec22f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.8-1 | 6.1.8-1 |
| linux | linux_kernel | >= 0 < 6.1.8-1 | 6.1.8-1 |
| linux | linux_kernel | >= 0 < 6.1.8-1 | 6.1.8-1 |
| linux | linux_kernel | >= 6.1 < 6.1.8 | 6.1.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-52902: In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree
osv·2024-08-21·CVSS 5.5
CVE-2023-52902 [MEDIUM] CVE-2023-52902: In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree
In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree nodes may leak if the error path to "error_just_free" is taken. Fix this by moving the freeing of the maple tree nodes to a shared location for all error paths.
GHSA
GHSA-jgx4-86q4-38fm: In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tr
ghsa_unreviewed·2024-08-21
CVE-2023-52902 [MEDIUM] CWE-401 GHSA-jgx4-86q4-38fm: In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tr
In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tree nodes may leak if the error path to
"error_just_free" is taken. Fix this by moving the freeing of the maple
tree nodes to a shared location for all error paths.
Red Hat
kernel: nommu: fix memory leak in do_mmap() error path
vendor_redhat·2024-08-21·CVSS 5.5
CVE-2023-52902 [MEDIUM] CWE-401 kernel: nommu: fix memory leak in do_mmap() error path
kernel: nommu: fix memory leak in do_mmap() error path
In the Linux kernel, the following vulnerability has been resolved:
nommu: fix memory leak in do_mmap() error path
The preallocation of the maple tree nodes may leak if the error path to
"error_just_free" is taken. Fix this by moving the freeing of the maple
tree nodes to a shared location for all error paths.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Will not fix
Debian
CVE-2023-52902: linux - In the Linux kernel, the following vulnerability has been resolved: nommu: fix ...
vendor_debian·2023·CVSS 5.5
CVE-2023-52902 [MEDIUM] CVE-2023-52902: linux - In the Linux kernel, the following vulnerability has been resolved: nommu: fix ...
In the Linux kernel, the following vulnerability has been resolved: nommu: fix memory leak in do_mmap() error path The preallocation of the maple tree nodes may leak if the error path to "error_just_free" is taken. Fix this by moving the freeing of the maple tree nodes to a shared location for all error paths.
Scope: local
bookworm: resolved (fixed in 6.1.8-1)
bullseye: resolved
forky: resolved (fixed in 6.1.8-1)
sid: resolved (fixed in 6.1.8-1)
trixie: resolved (fixed in 6.1.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-21
Published