cbcvebase.
CVE-2023-53221
published 2025-09-15

CVE-2023-53221: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix memleak due to fentry attach failure If it fails to attach fentry, the allocated…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix memleak due to fentry attach failure If it fails to attach fentry, the allocated bpf trampoline image will be left in the system. That can be verified by checking /proc/kallsyms. This meamleak can be verified by a simple bpf program as follows: SEC("fentry/trap_init") int fentry_run() { return 0; } It will fail to attach trap_init because this function is freed after kernel init, and then we can find the trampoline image is left in the system by checking /proc/kallsyms. $ tail /proc/kallsyms ffffffffc0613000 t bpf_trampoline_6442453466_1 [bpf] ffffffffc06c3000 t bpf_trampoline_6442453466_1 [bpf] $ bpftool btf dump file /sys/kernel/btf/vmlinux | grep "FUNC 'trap_init'" [2522] FUNC 'trap_init' type_id=119 linkage=static $ echo $((6442453466 & 0x7fffffff)) 2522 Note that there are two left bpf trampoline images, that is because the libbpf will fallback to raw tracepoint if -EINVAL is returned.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.28 < 5.115.11
linuxlinux>= 5.11.11 < 5.125.12
linuxlinux>= e21aa341785c679dd409c8cb71f864c00fe6c463 < 20109ddd5bea2c24d790debf5d02584ef24c3f5e20109ddd5bea2c24d790debf5d02584ef24c3f5e
linuxlinux>= e21aa341785c679dd409c8cb71f864c00fe6c463 < f72c67d1a82dada7d6d504c806e111e913721a30f72c67d1a82dada7d6d504c806e111e913721a30
linuxlinux>= e21aa341785c679dd409c8cb71f864c00fe6c463 < 6aa27775db63ba8c7c73891c7dfb71ddc230c48d6aa27775db63ba8c7c73891c7dfb71ddc230c48d
linuxlinux>= e21aa341785c679dd409c8cb71f864c00fe6c463 < 108598c39eefbedc9882273ac0df96127a629220108598c39eefbedc9882273ac0df96127a629220
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 5.10.28 < 5.115.11
linuxlinux_kernel>= 5.11.11 < 5.125.12
linuxlinux_kernel>= 5.12.1 < 6.1.396.1.39
linuxlinux_kernel>= 6.2 < 6.3.136.3.13
linuxlinux_kernel>= 6.4 < 6.4.46.4.4
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.