CVE-2023-53241Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: call op_release, even when op_func returns an error For ops with "trivial" replies, nfsd4_encode_operation will shortcut most of the encoding work and skip to just marshalling up the status. One of the things it skips is calling op_release. This could cause a memory leak in the layoutget codepath if there is an error at an inopportune time. Have the compound processing engine always call op_release, even when op_func se

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.145.10.220+4
Debianlinux/linux_kernel< 5.10.221-1+3
CVEListV5linux/linux34b1744c91ccd44811005822106945fa80ecbff265a33135e91e6dd661ecdf1194b9d90c49ae3570+5
debiandebian/linux< linux 6.1.25-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8mj9-585g-24hv: In the Linux kernel, the following vulnerability has been resolved: nfsd: call op_release, even when op_func returns an error For ops with "trivial"2025-09-15
OSV
CVE-2023-53241: In the Linux kernel, the following vulnerability has been resolved: nfsd: call op_release, even when op_func returns an error For ops with "trivial" r2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: nfsd: call op_release, even when op_func returns an error2025-09-15
Debian
CVE-2023-53241: linux - In the Linux kernel, the following vulnerability has been resolved: nfsd: call ...2023
CVE-2023-53241 — Linux vulnerability | cvebase