cbcvebase.
CVE-2023-53255
published 2025-09-15

CVE-2023-53255: In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: Fix a potential resource leak in svc_create_memory_pool()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: Fix a potential resource leak in svc_create_memory_pool() svc_create_memory_pool() is only called from stratix10_svc_drv_probe(). Most of resources in the probe are managed, but not this memremap() call. There is also no memunmap() call in the file. So switch to devm_memremap() to avoid a resource leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < e3373e6b6c79aff698442b00d20c9f285d296e46e3373e6b6c79aff698442b00d20c9f285d296e46
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < c04ed61ebf01968d7699b121663982493ed577fbc04ed61ebf01968d7699b121663982493ed577fb
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < 974ac045a05ad12a0b4578fb303f00dcc22f3aba974ac045a05ad12a0b4578fb303f00dcc22f3aba
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < cb8a31a56df8492fb0d900959238e1a3ff8b8981cb8a31a56df8492fb0d900959238e1a3ff8b8981
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < 7363de081c793e47866cb54ce7cb8a480cffc2597363de081c793e47866cb54ce7cb8a480cffc259
linuxlinux>= 7ca5ce896524f5292e610b27d168269e5ab74951 < 1995f15590ca222f91193ed11461862b450abfd61995f15590ca222f91193ed11461862b450abfd6
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.0 < 5.4.2515.4.251
linuxlinux_kernel>= 5.11 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16 < 6.1.406.1.40
linuxlinux_kernel>= 5.5 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2 < 6.4.56.4.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.