CVE-2023-53568
published 2025-10-04CVE-2023-53568: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: don't leak memory if dev_set_name() fails
When dev_set_name() fails, zcdn_create() doesn't free the newly
allocated resources. Do it.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 6b0cb9c055843777b374309503d89eabeb769355 | 6b0cb9c055843777b374309503d89eabeb769355 |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 0878052579cb2773caee64812a811edcab6b5a55 | 0878052579cb2773caee64812a811edcab6b5a55 |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 131cd74a8e38d75239f2c81dfee53d6554eb8bf8 | 131cd74a8e38d75239f2c81dfee53d6554eb8bf8 |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 147d8da33a2c2195ec63acd56cd7d80a3458c253 | 147d8da33a2c2195ec63acd56cd7d80a3458c253 |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 174f11ef1615ec3ab1e2189685864433c0d855a2 | 174f11ef1615ec3ab1e2189685864433c0d855a2 |
| linux | linux | >= 00fab2350e6b91e57b3cdcd5d9f01056775a921d < 6252f47b78031979ad919f971dc8468b893488bd | 6252f47b78031979ad919f971dc8468b893488bd |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 4.20 < 5.4.257 | 5.4.257 |
| linux | linux_kernel | >= 5.11 < 5.15.132 | 5.15.132 |
| linux | linux_kernel | >= 5.16 < 6.1.54 | 6.1.54 |
| linux | linux_kernel | >= 5.5 < 5.10.195 | 5.10.195 |
| linux | linux_kernel | >= 6.2 < 6.5.4 | 6.5.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53568: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails,
osv·2025-10-04·CVSS 5.5
CVE-2023-53568 [MEDIUM] CVE-2023-53568: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails,
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails, zcdn_create() doesn't free the newly allocated resources. Do it.
GHSA
GHSA-qwh3-qmrm-hv2r: In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: don't leak memory if dev_set_name() fails
When dev_set_name() fails
ghsa_unreviewed·2025-10-04
CVE-2023-53568 [MEDIUM] CWE-401 GHSA-qwh3-qmrm-hv2r: In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: don't leak memory if dev_set_name() fails
When dev_set_name() fails
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: don't leak memory if dev_set_name() fails
When dev_set_name() fails, zcdn_create() doesn't free the newly
allocated resources. Do it.
Red Hat
kernel: s390/zcrypt: don't leak memory if dev_set_name() fails
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53568 [MEDIUM] CWE-772 kernel: s390/zcrypt: don't leak memory if dev_set_name() fails
kernel: s390/zcrypt: don't leak memory if dev_set_name() fails
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: don't leak memory if dev_set_name() fails
When dev_set_name() fails, zcdn_create() doesn't free the newly
allocated resources. Do it.
A resource leak was found in the Linux kernel's s390 cryptographic device driver in the device creation path. When the dev_set_name function fails during creation of a zcrypt device node, the zcdn_create function returns an error without freeing the newly allocated device structure and associated resources. This creates a permanent memory leak, leading to resource exhaustion and denial of service.
Statement: The z/Architecture cryptographic device interface allows creation of additional device nodes for accessing
Debian
CVE-2023-53568: linux - In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt...
vendor_debian·2023·CVSS 5.5
CVE-2023-53568 [MEDIUM] CVE-2023-53568: linux - In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt...
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails, zcdn_create() doesn't free the newly allocated resources. Do it.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0878052579cb2773caee64812a811edcab6b5a55https://git.kernel.org/stable/c/131cd74a8e38d75239f2c81dfee53d6554eb8bf8https://git.kernel.org/stable/c/147d8da33a2c2195ec63acd56cd7d80a3458c253https://git.kernel.org/stable/c/174f11ef1615ec3ab1e2189685864433c0d855a2https://git.kernel.org/stable/c/6252f47b78031979ad919f971dc8468b893488bdhttps://git.kernel.org/stable/c/6b0cb9c055843777b374309503d89eabeb769355
2025-10-04
Published