cbcvebase.
CVE-2023-53611
published 2025-10-04

CVE-2023-53611: In the Linux kernel, the following vulnerability has been resolved: ipmi_si: fix a memleak in try_smi_init() Kmemleak reported the following leak info in…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ipmi_si: fix a memleak in try_smi_init() Kmemleak reported the following leak info in try_smi_init(): unreferenced object 0xffff00018ecf9400 (size 1024): comm "modprobe", pid 2707763, jiffies 4300851415 (age 773.308s) backtrace: [] __kmalloc+0x4b8/0x7b0 [] try_smi_init+0x148/0x5dc [ipmi_si] [] 0xffff800081b10148 [] do_one_initcall+0x64/0x2a4 [] do_init_module+0x50/0x300 [] load_module+0x7a8/0x9e0 [] __se_sys_init_module+0x104/0x180 [] __arm64_sys_init_module+0x24/0x30 [] el0_svc_common.constprop.0+0x94/0x250 [] do_el0_svc+0x48/0xe0 [] el0_svc+0x24/0x3c [] el0_sync_handler+0x160/0x164 [] el0_sync+0x160/0x180 The problem was that when an error occurred before handlers registration and after allocating `new_smi->si_sm`, the variable wouldn't be freed in the error handling afterwards since `shutdown_smi()` hadn't been registered yet. Fix it by adding a `kfree()` in the error handling path in `try_smi_init()`.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < b9bc8fbb2d416ce87f0342478dc9fcfd79f2c65fb9bc8fbb2d416ce87f0342478dc9fcfd79f2c65f
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < f53ab5a2bf20fed59a2f7542d3453228b8056358f53ab5a2bf20fed59a2f7542d3453228b8056358
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < 5c5f02e16b919c8cb6024dc3778c8d8f1fb1f26b5c5f02e16b919c8cb6024dc3778c8d8f1fb1f26b
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < cbb7d8a4b4beb3061b3a1847a742983a01dca381cbb7d8a4b4beb3061b3a1847a742983a01dca381
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < 09cb2a71b2e982015fe0464f28da1ab42b8e637509cb2a71b2e982015fe0464f28da1ab42b8e6375
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < 1bfcfea0fae0d0a6c6ff5543e6d704b3807b83ce1bfcfea0fae0d0a6c6ff5543e6d704b3807b83ce
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < 7291af9a738d936c2d6869d030711dceb68404d07291af9a738d936c2d6869d030711dceb68404d0
linuxlinux>= 7960f18a56475bf2177c5ff56c72eb4c12c56440 < 6cf1a126de2992b4efe1c3c4d398f8de4aed6e3f6cf1a126de2992b4efe1c3c4d398f8de4aed6e3f
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 4.18 < 4.19.2954.19.295
linuxlinux_kernel>= 4.20 < 5.4.2575.4.257
linuxlinux_kernel>= 5.11 < 5.15.1325.15.132
linuxlinux_kernel>= 5.16 < 6.1.536.1.53
linuxlinux_kernel>= 5.5 < 5.10.1955.10.195
linuxlinux_kernel>= 6.2 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.