CVE-2023-53568Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails, zcdn_create() doesn't free the newly allocated resources. Do it.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.205.4.257+4
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linux00fab2350e6b91e57b3cdcd5d9f01056775a921d6b0cb9c055843777b374309503d89eabeb769355+6
debiandebian/linux< linux 6.1.55-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53568: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails,2025-10-04
GHSA
GHSA-qwh3-qmrm-hv2r: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: don't leak memory if dev_set_name() fails When dev_set_name() fails2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: s390/zcrypt: don't leak memory if dev_set_name() fails2025-10-04
Debian
CVE-2023-53568: linux - In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt...2023