CVE-2023-53518
published 2025-10-01CVE-2023-53518: In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix leak in devfreq_dev_release() srcu_init_notifier_head() allocates…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
PM / devfreq: Fix leak in devfreq_dev_release()
srcu_init_notifier_head() allocates resources that need to be released
with a srcu_cleanup_notifier_head() call.
Reported by kmemleak.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 7462483446cb9986568ad7adae746ce5f18d2968 | 7462483446cb9986568ad7adae746ce5f18d2968 |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 64e6e0dc2d578c0a9e31cb4edd719f0a3ed98f6d | 64e6e0dc2d578c0a9e31cb4edd719f0a3ed98f6d |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 29811f4b8255d4238cf326f3bb7129784766beab | 29811f4b8255d4238cf326f3bb7129784766beab |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < ab192e5e5d3b48415909a8408acfd007a607bcc0 | ab192e5e5d3b48415909a8408acfd007a607bcc0 |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 111bafa210ae546bee7644be730c42df9c35b66e | 111bafa210ae546bee7644be730c42df9c35b66e |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 8918025feb2f5f7c73f2495c158f22997e25cb02 | 8918025feb2f5f7c73f2495c158f22997e25cb02 |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 1640e9c72173911ad0fddb05012c01eafe082c4e | 1640e9c72173911ad0fddb05012c01eafe082c4e |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 3354c401c68d70567d1ef25d12f4e22a7813a3c6 | 3354c401c68d70567d1ef25d12f4e22a7813a3c6 |
| linux | linux | >= 0fe3a66410a3ba96679be903f1e287d7a0a264a9 < 5693d077595de721f9ddbf9d37f40e5409707dfe | 5693d077595de721f9ddbf9d37f40e5409707dfe |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 4.15 < 4.19.295 | 4.19.295 |
| linux | linux_kernel | >= 4.20 < 5.4.257 | 5.4.257 |
| linux | linux_kernel | >= 4.7 < 4.14.326 | 4.14.326 |
| linux | linux_kernel | >= 5.11 < 5.15.132 | 5.15.132 |
| linux | linux_kernel | >= 5.16 < 6.1.53 | 6.1.53 |
| linux | linux_kernel | >= 5.5 < 5.10.195 | 5.10.195 |
| linux | linux_kernel | >= 6.2 < 6.4.16 | 6.4.16 |
| linux | linux_kernel | >= 6.5 < 6.5.3 | 6.5.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x97q-xc6x-vxw7: In the Linux kernel, the following vulnerability has been resolved:
PM / devfreq: Fix leak in devfreq_dev_release()
srcu_init_notifier_head() alloca
ghsa_unreviewed·2025-10-01
CVE-2023-53518 [MEDIUM] CWE-401 GHSA-x97q-xc6x-vxw7: In the Linux kernel, the following vulnerability has been resolved:
PM / devfreq: Fix leak in devfreq_dev_release()
srcu_init_notifier_head() alloca
In the Linux kernel, the following vulnerability has been resolved:
PM / devfreq: Fix leak in devfreq_dev_release()
srcu_init_notifier_head() allocates resources that need to be released
with a srcu_cleanup_notifier_head() call.
Reported by kmemleak.
OSV
CVE-2023-53518: In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix leak in devfreq_dev_release() srcu_init_notifier_head() allocate
osv·2025-10-01·CVSS 5.5
CVE-2023-53518 [MEDIUM] CVE-2023-53518: In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix leak in devfreq_dev_release() srcu_init_notifier_head() allocate
In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix leak in devfreq_dev_release() srcu_init_notifier_head() allocates resources that need to be released with a srcu_cleanup_notifier_head() call. Reported by kmemleak.
Red Hat
kernel: Linux kernel: Memory leak in PM / devfreq can lead to denial of service
vendor_redhat·2025-10-01·CVSS 5.5
CVE-2023-53518 [MEDIUM] CWE-772 kernel: Linux kernel: Memory leak in PM / devfreq can lead to denial of service
kernel: Linux kernel: Memory leak in PM / devfreq can lead to denial of service
In the Linux kernel, the following vulnerability has been resolved:
PM / devfreq: Fix leak in devfreq_dev_release()
srcu_init_notifier_head() allocates resources that need to be released
with a srcu_cleanup_notifier_head() call.
Reported by kmemleak.
A flaw was found in the Linux kernel's Power Management (PM) / devfreq subsystem. This vulnerability is a memory leak, where resources allocated by srcu_init_notifier_head() are not properly released. A local attacker could exploit this by repeatedly triggering the affected code, leading to resource exhaustion and a denial of service (DoS) on the system.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) -
Debian
CVE-2023-53518: linux - In the Linux kernel, the following vulnerability has been resolved: PM / devfre...
vendor_debian·2023·CVSS 5.5
CVE-2023-53518 [MEDIUM] CVE-2023-53518: linux - In the Linux kernel, the following vulnerability has been resolved: PM / devfre...
In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix leak in devfreq_dev_release() srcu_init_notifier_head() allocates resources that need to be released with a srcu_cleanup_notifier_head() call. Reported by kmemleak.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/111bafa210ae546bee7644be730c42df9c35b66ehttps://git.kernel.org/stable/c/1640e9c72173911ad0fddb05012c01eafe082c4ehttps://git.kernel.org/stable/c/29811f4b8255d4238cf326f3bb7129784766beabhttps://git.kernel.org/stable/c/3354c401c68d70567d1ef25d12f4e22a7813a3c6https://git.kernel.org/stable/c/5693d077595de721f9ddbf9d37f40e5409707dfehttps://git.kernel.org/stable/c/64e6e0dc2d578c0a9e31cb4edd719f0a3ed98f6dhttps://git.kernel.org/stable/c/7462483446cb9986568ad7adae746ce5f18d2968https://git.kernel.org/stable/c/8918025feb2f5f7c73f2495c158f22997e25cb02https://git.kernel.org/stable/c/ab192e5e5d3b48415909a8408acfd007a607bcc0
2025-10-01
Published