CVE-2023-53830
published 2025-12-09CVE-2023-53830: In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriving a…
PriorityP419low5.5
EPSS
0.23%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0fdf10e5fc964c315cf131a2eaab9cc531a9f40f < b9396d991abe8d1ac31a043274ab20b49f92c2e6 | b9396d991abe8d1ac31a043274ab20b49f92c2e6 |
| linux | linux | >= 0fdf10e5fc964c315cf131a2eaab9cc531a9f40f < 9071525bfcb1f5674117dbed3eca0cd7b122813b | 9071525bfcb1f5674117dbed3eca0cd7b122813b |
| linux | linux | >= 0fdf10e5fc964c315cf131a2eaab9cc531a9f40f < 5f99014c19fa50a5719c0bb78143282632675893 | 5f99014c19fa50a5719c0bb78143282632675893 |
| linux | linux | >= 0fdf10e5fc964c315cf131a2eaab9cc531a9f40f < a3c4c053014585dcf20f4df954791b74d8a8afcd | a3c4c053014585dcf20f4df954791b74d8a8afcd |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 5.14.0 < 5.15.107 | 5.15.107 |
| linux | linux_kernel | >= 5.16.0 < 6.1.24 | 6.1.24 |
| linux | linux_kernel | >= 6.2.0 < 6.2.11 | 6.2.11 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
vendor_redhat·2025-12-09·CVSS 5.5
CVE-2023-53830 [LOW] CWE-772 kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
A memory leak was found in the Lenovo ThinkPad LMI driver in the Linux kernel. When current_value_show() encounters malformed item strings from tlmi_setting(), it returns early without freeing the allocated memory. Repeated reads of sysfs attributes could gradually exhaust kernel memory.
Statement: This affects only Lenovo Think
Debian
CVE-2023-53830: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
vendor_debian·2023
CVE-2023-53830 CVE-2023-53830: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriving a item string with tlmi_setting(), the result has to be freed using kfree(). In current_value_show() however, malformed item strings are not freed, causing a memory leak. Fix this by eliminating the early return responsible for this.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
GHSA
GHSA-rhg6-xfgx-wqj9: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retr
ghsa_unreviewed·2025-12-09
CVE-2023-53830 GHSA-rhg6-xfgx-wqj9: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retr
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
OSV
CVE-2023-53830: In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriv
osv·2025-12-09
CVE-2023-53830 CVE-2023-53830: In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriv
In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leak when showing current settings When retriving a item string with tlmi_setting(), the result has to be freed using kfree(). In current_value_show() however, malformed item strings are not freed, causing a memory leak. Fix this by eliminating the early return responsible for this.
OSV
platform/x86: think-lmi: Fix memory leak when showing current settings
osv·2025-12-09
CVE-2023-53830 platform/x86: think-lmi: Fix memory leak when showing current settings
platform/x86: think-lmi: Fix memory leak when showing current settings
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53830 kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
bugzilla·2025-12-09
CVE-2023-53830 [LOW] CVE-2023-53830 kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
CVE-2023-53830 kernel: platform/x86: think-lmi: Fix memory leak when showing current settings
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025120953-CVE-2023-53830-7785@gregkh/T
Wiz
CVE-2023-53830 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-53830 CVE-2023-53830 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-53830 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix memory leak when showing current settings
When retriving a item string with tlmi_setting(), the result has to be
freed using kfree(). In current_value_show() however, malformed
item strings are not freed, causing a memory leak.
Fix this by eliminating the early return responsible for this.
Source : NVD
Published December 9, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ocfs2-kmp-de
2025-12-09
Published