cbcvebase.
CVE-2023-53746
published 2025-12-08

CVE-2023-53746: In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function…

PriorityP422low5.5
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function invoked to release the matrix device uses the dev_get_drvdata(device *dev) function to retrieve the pointer to the vfio_matrix_dev object in order to free its storage. The problem is, this object is not stored as drvdata with the device; since the kfree function will accept a NULL pointer, the memory for the vfio_matrix_dev object is never freed. Since the device being released is contained within the vfio_matrix_dev object, the container_of macro will be used to retrieve its pointer.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < 5195de1d5f66b276683240a896783f7f43c4f6645195de1d5f66b276683240a896783f7f43c4f664
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < ee17dea3072dec0bc34399a32fa884e26342e4eaee17dea3072dec0bc34399a32fa884e26342e4ea
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < aa2bff25e9bb10c935c7ffe3d5f5975bdccb1749aa2bff25e9bb10c935c7ffe3d5f5975bdccb1749
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < 6a40fda14b4be3e38f03cc42ffd4efbc64fb3e676a40fda14b4be3e38f03cc42ffd4efbc64fb3e67
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < 7b6a02f5bf15931464c79dfd487c57f76aae34967b6a02f5bf15931464c79dfd487c57f76aae3496
linuxlinux>= 1fde573413b549d52183382e639c1d6ce88f5959 < 8f8cf767589f2131ae5d40f3758429095c701c848f8cf767589f2131ae5d40f3758429095c701c84
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 4.20.0 < 5.4.2405.4.240
linuxlinux_kernel>= 5.11.0 < 5.15.1065.15.106
linuxlinux_kernel>= 5.16.0 < 6.1.236.1.23
linuxlinux_kernel>= 5.5.0 < 5.10.1775.10.177
linuxlinux_kernel>= 6.2.0 < 6.2.106.2.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.