CVE-2023-53724

UnknownEPSS 0.19%

Last modified

CVE-2023-53724 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mfd: pcf50633-adc: Fix potential memleak in pcf50633_adc_async_read() `req` is allocated in pcf50633_adc_async_read(), but adc_enqueue_request() could fail to insert the `req` into queue. We need to check the return value and free it in the case of failure.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: mfd: pcf50633-adc: Fix potential memleak in pcf50633_adc_async_read() `req` is allocated in pcf50633_adc_async_read(), but adc_enqueue_request() could fail to insert the `req` into queue. We need to check the return value and free it in the case of failure.

Metrics

EPSS Probability
0.19%

9.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 08c3e06a5eb27d43b712adef18379f8464425e71, < 66616eed76dfa6f3e442907760325a023c6da7e2; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 41cdf082ae006ea002135dfaf43b2897de3bded8; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 588edb4fb1f1e6487a0f60a5f7b9a24d2d0c9f8e; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 3ee13bdf0d25ae8752ae6185b6d13bbb0d5a8e30; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 6a8a02dcfae13ab07dc7bed2b409cec7f3d32e92; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 9cca3a4933ca365cc664d5eefb0f942374ea8b41; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < a62a5e79202967176a9c1a04e477860779accd6c; >= 08c3e06a5eb27d43b712adef18379f8464425e71, < 8b450dcff23aa254844492831a8e2b508a9d522d
LinuxLinux2.6.29

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-53724?
In the Linux kernel, the following vulnerability has been resolved: mfd: pcf50633-adc: Fix potential memleak in pcf50633_adc_async_read() `req` is allocated in pcf50633_adc_async_read(), but adc_enqueue_request() could fail to insert the `req` into queue. We need to check the return value and free it in the case of failure.
How severe is CVE-2023-53724?
Severity scoring for CVE-2023-53724 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-53724?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-53724?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST