cbcvebase.
CVE-2023-53670
published 2025-10-07

CVE-2023-53670: In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix dev_pm_qos memleak Call dev_pm_qos_hide_latency_tolerance() in the error…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix dev_pm_qos memleak Call dev_pm_qos_hide_latency_tolerance() in the error unwind patch to avoid following kmemleak:- blktests (master) # kmemleak-clear; ./check nvme/044; blktests (master) # kmemleak-scan ; kmemleak-show nvme/044 (Test bi-directional authentication) [passed] runtime 2.111s ... 2.124s unreferenced object 0xffff888110c46240 (size 96): comm "nvme", pid 33461, jiffies 4345365353 (age 75.586s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] kmalloc_trace+0x25/0x90 [] dev_pm_qos_update_user_latency_tolerance+0x6f/0x100 [] nvme_init_ctrl+0x38e/0x410 [nvme_core] [] 0xffffffffc05e88b3 [] 0xffffffffc05744cb [] vfs_write+0xc5/0x3c0 [] ksys_write+0x5f/0xe0 [] do_syscall_64+0x3b/0x90 [] entry_SYSCALL_64_after_hwframe+0x72/0xdc

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= f50fff73d620cd6e8f48bc58d4f1c944615a3fea < e1379e067b9485e5af03399fe3f0d39bccb023ade1379e067b9485e5af03399fe3f0d39bccb023ad
linuxlinux>= f50fff73d620cd6e8f48bc58d4f1c944615a3fea < 7237c26431cc78e5ec3259f4350f3dd58f6a43197237c26431cc78e5ec3259f4350f3dd58f6a4319
linuxlinux>= f50fff73d620cd6e8f48bc58d4f1c944615a3fea < 2ed9a89192e3192e5fea7ff6475c8722513f325e2ed9a89192e3192e5fea7ff6475c8722513f325e
linuxlinux>= f50fff73d620cd6e8f48bc58d4f1c944615a3fea < 7ed5cf8e6d9bfb6a78d0471317edff14f0f2b4dd7ed5cf8e6d9bfb6a78d0471317edff14f0f2b4dd
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 6.0 < 6.1.396.1.39
linuxlinux_kernel>= 6.2 < 6.3.136.3.13
linuxlinux_kernel>= 6.4 < 6.4.46.4.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.