CVE-2023-53708
published 2025-10-22CVE-2023-53708: In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed firmware…
PriorityP419low4
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE`
objects while evaluating the AMD LPS0 _DSM, there will be a memory
leak. Explicitly guard against this.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 146f1ed852a87b802ed6e71c31e189c64871383c < 7b7964cd9db30bc84808a40d13a0633b4313f149 | 7b7964cd9db30bc84808a40d13a0633b4313f149 |
| linux | linux | >= 146f1ed852a87b802ed6e71c31e189c64871383c < 1ea7e47807279369c82718efd2677ea25c6579e3 | 1ea7e47807279369c82718efd2677ea25c6579e3 |
| linux | linux | >= 146f1ed852a87b802ed6e71c31e189c64871383c < 9e8bbde9293151430884aed882a88eaa22298f72 | 9e8bbde9293151430884aed882a88eaa22298f72 |
| linux | linux | >= 146f1ed852a87b802ed6e71c31e189c64871383c < 883cf0d4cf288313b71146ddebdf5d647b76c78b | 883cf0d4cf288313b71146ddebdf5d647b76c78b |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.133 | 5.15.133 |
| linux | linux_kernel | >= 5.16.0 < 6.1.55 | 6.1.55 |
| linux | linux_kernel | >= 6.2.0 < 6.5.5 | 6.5.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
vendor_redhat·2025-10-22·CVSS 4.0
CVE-2023-53708 [LOW] kernel: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
kernel: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE`
objects while evaluating the AMD LPS0 _DSM, there will be a memory
leak. Explicitly guard against this.
A memory leak was found in the Linux kernel's ACPI x86 suspend-to-idle implementation in the AMD Low Power S0 (LPS0) DSM evaluation code. A system with malformed ACPI firmware that returns multiple ACPI_TYPE_PACKAGE objects during _DSM evaluation can trigger repeated memory allocations that are never freed. This leads to gradual memory exhaustion and potential denial of service.
Statement: The AMD LPS0 DSM handler expects a
Debian
CVE-2023-53708: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: ...
vendor_debian·2023
CVE-2023-53708 CVE-2023-53708: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: ...
In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE` objects while evaluating the AMD LPS0 _DSM, there will be a memory leak. Explicitly guard against this.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
OSV
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
osv·2025-10-22
CVE-2023-53708 ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE`
objects while evaluating the AMD LPS0 _DSM, there will be a memory
leak. Explicitly guard against this.
GHSA
GHSA-2f48-8mh4-9hm3: In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly construct
ghsa_unreviewed·2025-10-22
CVE-2023-53708 GHSA-2f48-8mh4-9hm3: In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly construct
In the Linux kernel, the following vulnerability has been resolved:
ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE`
objects while evaluating the AMD LPS0 _DSM, there will be a memory
leak. Explicitly guard against this.
OSV
CVE-2023-53708: In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed
osv·2025-10-22
CVE-2023-53708 CVE-2023-53708: In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed
In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE` objects while evaluating the AMD LPS0 _DSM, there will be a memory leak. Explicitly guard against this.
No detection rules found.
No public exploits indexed.
2025-10-22
Published