cbcvebase.
CVE-2023-53436
published 2025-09-18

CVE-2023-53436: In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible memory leak if device_add() fails If device_add() returns error…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to give up the reference in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 789275f7c0544374d40bc8d9c81f96751a41df45789275f7c0544374d40bc8d9c81f96751a41df45
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < f830968d464f55e11bc9260a132fc77daa266aa3f830968d464f55e11bc9260a132fc77daa266aa3
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < cea09922f5f75652d55b481ee34011fc7f19868bcea09922f5f75652d55b481ee34011fc7f19868b
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 58889d5ad74cbc1c9595db74e13522b58b69b0ec58889d5ad74cbc1c9595db74e13522b58b69b0ec
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 461f8ac666fa232afee5ed6420099913ec4e4ba2461f8ac666fa232afee5ed6420099913ec4e4ba2
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 7723a5d5d187626c4c640842e522cf4e9e39492e7723a5d5d187626c4c640842e522cf4e9e39492e
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < ed0acb1ee2e9322b96611635a9ca9303d15ac76ced0acb1ee2e9322b96611635a9ca9303d15ac76c
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 41320b18a0e0dfb236dba4edb9be12dba187815641320b18a0e0dfb236dba4edb9be12dba1878156
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 4.15 < 4.19.2924.19.292
linuxlinux_kernel>= 4.2 < 4.14.3234.14.323
linuxlinux_kernel>= 4.20 < 5.4.2545.4.254
linuxlinux_kernel>= 5.11 < 5.15.1275.15.127
linuxlinux_kernel>= 5.16 < 6.1.466.1.46
linuxlinux_kernel>= 5.5 < 5.10.1915.10.191
linuxlinux_kernel>= 6.2 < 6.4.116.4.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.