cbcvebase.
CVE-2023-53303
published 2025-09-16

CVE-2023-53303: In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix possible memory leak for vcap_dup_rule() Inject fault When…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix possible memory leak for vcap_dup_rule() Inject fault When select CONFIG_VCAP_KUNIT_TEST, the below memory leak occurs. If kzalloc() for duprule succeeds, but the following kmemdup() fails, the duprule, ckf and caf memory will be leaked. So kfree them in the error path. unreferenced object 0xffff122744c50600 (size 192): comm "kunit_try_catch", pid 346, jiffies 4294896122 (age 911.812s) hex dump (first 32 bytes): 10 27 00 00 04 00 00 00 1e 00 00 00 2c 01 00 00 .'..........,... 00 00 00 00 00 00 00 00 18 06 c5 44 27 12 ff ff ...........D'... backtrace: [] __kmem_cache_alloc_node+0x274/0x2f8 [] kmalloc_trace+0x38/0x88 [] vcap_dup_rule+0x50/0x460 [] vcap_add_rule+0x8cc/0x1038 [] test_vcap_xn_rule_creator.constprop.0.isra.0+0x238/0x494 [] vcap_api_rule_remove_in_front_test+0x1ac/0x698 [] kunit_try_run_case+0xe0/0x20c [] kunit_generic_run_threadfn_adapter+0x50/0x94 [] kthread+0x2e8/0x374 [] ret_from_fork+0x10/0x20

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.5.6-1 (forky)linux 6.5.6-1 (forky)
linuxlinux
linuxlinux>= 814e7693207f1bd936d600f9b5467f133e3d6e40 < a26ba60413b2c8f95daf0ee0152cf82abd7bfbe4a26ba60413b2c8f95daf0ee0152cf82abd7bfbe4
linuxlinux>= 814e7693207f1bd936d600f9b5467f133e3d6e40 < 281f65d29d6da1a9b6907fb0b145aaf34f4e4822281f65d29d6da1a9b6907fb0b145aaf34f4e4822
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 6.3 < 6.5.46.5.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.