CVE-2023-53830Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 90.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriving a item string with tlmi_setting(), the result has to be freed using kfree(). In current_value_show() however, malformed item strings are not freed, causing a memory leak. Fix this by eliminating the early return responsible for this.

Affected Packages4 packages

Linuxlinux/linux_kernel5.14.05.15.107+2
Debianlinux/linux_kernel< 6.1.25-1+2
CVEListV5linux/linux0fdf10e5fc964c315cf131a2eaab9cc531a9f40fb9396d991abe8d1ac31a043274ab20b49f92c2e6+4
debiandebian/linux< linux 6.1.25-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-rhg6-xfgx-wqj9: In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retr2025-12-09
OSV
CVE-2023-53830: In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriv2025-12-09
OSV
platform/x86: think-lmi: Fix memory leak when showing current settings2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: platform/x86: think-lmi: Fix memory leak when showing current settings2025-12-09
Debian
CVE-2023-53830: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-53830 Impact, Exploitability, and Mitigation Steps | Wiz