CVE-2023-53792Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix memory leak in dhchap_ctrl_secret Free dhchap_secret in nvme_ctrl_dhchap_ctrl_secret_store() before we return when nvme_auth_generate_key() returns error.

Affected Packages4 packages

Linuxlinux/linux_kernel6.0.06.1.39+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linuxf50fff73d620cd6e8f48bc58d4f1c944615a3fea43d0724d756a13694f612a8a151f835ad6425b93+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
nvme-core: fix memory leak in dhchap_ctrl_secret2025-12-09
OSV
CVE-2023-53792: In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix memory leak in dhchap_ctrl_secret Free dhchap_secret in nvme_ctrl_d2025-12-09
GHSA
GHSA-fcxh-7g3m-939f: In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix memory leak in dhchap_ctrl_secret Free dhchap_secret in nvme_ctrl2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: nvme-core: fix memory leak in dhchap_ctrl_secret2025-12-09
Debian
CVE-2023-53792: linux - In the Linux kernel, the following vulnerability has been resolved: nvme-core: ...2023