cbcvebase.
CVE-2023-53449
published 2025-10-01

CVE-2023-53449: In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix potential memleak in dasd_eckd_init() `dasd_reserve_req` is allocated before…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix potential memleak in dasd_eckd_init() `dasd_reserve_req` is allocated before `dasd_vol_info_req`, and it also needs to be freed before the error returns, just like the other cases in this function.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < ee986d80acdef710a886be404308188ea11000c8ee986d80acdef710a886be404308188ea11000c8
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < a50e28d433acf22258f9f34831057387f04ef074a50e28d433acf22258f9f34831057387f04ef074
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < 544a552be0869231799784279d52704c4d314d33544a552be0869231799784279d52704c4d314d33
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < ef3a7ffc0a6f833578bc8d1dcb79d0633c7e4ec3ef3a7ffc0a6f833578bc8d1dcb79d0633c7e4ec3
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < aede5230d154b6b237985ec9df7ebbd1dce96810aede5230d154b6b237985ec9df7ebbd1dce96810
linuxlinux>= 9e12e54c7a8f616190beffb0f7ce778a86aec175 < 460e9bed82e49db1b823dcb4e421783854d86c40460e9bed82e49db1b823dcb4e421783854d86c40
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 5.11 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 5.3 < 5.4.2355.4.235
linuxlinux_kernel>= 5.5 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.