CVE-2023-53468Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1

Description

In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in alloc_wbufs() kmemleak reported a sequence of memory leaks, and show them as following: unreferenced object 0xffff8881575f8400 (size 1024): comm "mount", pid 19625, jiffies 4297119604 (age 20.383s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc+0x4d/0x150 [] ubifs_moun

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel2.6.275.4.235+4
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d1f206002c6bc302bface871ef3f72c0bbcaa931c+6
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rwqr-mq87-5p2c: In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in alloc_wbufs() kmemleak reported a sequence of memory l2025-10-01
OSV
CVE-2023-53468: In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in alloc_wbufs() kmemleak reported a sequence of memory lea2025-10-01

📋Vendor Advisories

2
Red Hat
kernel: ubifs: Fix memory leak in alloc_wbufs()2025-10-01
Debian
CVE-2023-53468: linux - In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix ...2023