CVE-2023-54005Missing Release of Memory after Effective Lifetime in Linux

7 documents6 sources
Severity
N/A
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: binder: fix memory leak in binder_init() In binder_init(), the destruction of binder_alloc_shrinker_init() is not performed in the wrong path, which will cause memory leaks. So this commit introduces binder_alloc_shrinker_exit() and calls it in the wrong path to fix that.

Affected Packages4 packages

Linuxlinux/linux_kernel4.14.04.14.324+6
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linuxf2517eb76f1f2f7f89761f9db2b202e89931738c486dd742ba186ea333664c517d6775b06b1448ca+8
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
binder: fix memory leak in binder_init()2025-12-24
OSV
CVE-2023-54005: In the Linux kernel, the following vulnerability has been resolved: binder: fix memory leak in binder_init() In binder_init(), the destruction of bind2025-12-24
GHSA
GHSA-5h2v-hcwg-qff4: In the Linux kernel, the following vulnerability has been resolved: binder: fix memory leak in binder_init() In binder_init(), the destruction of bi2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: binder: fix memory leak in binder_init()2025-12-24
Debian
CVE-2023-54005: linux - In the Linux kernel, the following vulnerability has been resolved: binder: fix...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54005 Impact, Exploitability, and Mitigation Steps | Wiz