CVE-2023-53697

UnknownEPSS 0.19%

Last modified

CVE-2023-53697 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: nvdimm: Fix memleak of pmu attr_groups in unregister_nvdimm_pmu() Memory pointed by 'nd_pmu->pmu.attr_groups' is allocated in function 'register_nvdimm_pmu' and is lost after 'kfree(nd_pmu)' call in function 'unregister_nvdimm_pmu'.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: nvdimm: Fix memleak of pmu attr_groups in unregister_nvdimm_pmu() Memory pointed by 'nd_pmu->pmu.attr_groups' is allocated in function 'register_nvdimm_pmu' and is lost after 'kfree(nd_pmu)' call in function 'unregister_nvdimm_pmu'.

Metrics

EPSS Probability
0.19%

9.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 0fab1ba6ad6ba1f76380f92ead95c6e861ef8116, < 500a6ff9c2a81348fe0f04e2deb758145e8ab94e; >= 0fab1ba6ad6ba1f76380f92ead95c6e861ef8116, < 4999f2ec5fde7c45e3ecafda5b78560cc1c7bdb5; >= 0fab1ba6ad6ba1f76380f92ead95c6e861ef8116, < 16259c80542ee8945aaa39cfc6a1809bcdc08ffe; >= 0fab1ba6ad6ba1f76380f92ead95c6e861ef8116, < 85ae42c72142346645e63c33835da947dfa008b3
LinuxLinux5.18

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-53697?
In the Linux kernel, the following vulnerability has been resolved: nvdimm: Fix memleak of pmu attr_groups in unregister_nvdimm_pmu() Memory pointed by 'nd_pmu->pmu.attr_groups' is allocated in function 'register_nvdimm_pmu' and is lost after 'kfree(nd_pmu)' call in function 'unregister_nvdimm_pmu'.
How severe is CVE-2023-53697?
Severity scoring for CVE-2023-53697 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-53697?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-53697?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST