CVE-2023-54252

UnknownEPSS 0.17%

Last modified

CVE-2023-54252 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

Metrics

EPSS Probability
0.17%

6.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= dae47bf0222e1e0eb6684c7e141b7170b0884a4c, < cccdb30935c82be805d3362a15680b95d5cb3ee0; >= f0a67ad7dce49d93570edc795e0312bb787f19bb, < 081da7b1c881828244b93b3befb7c18389f696bb; >= c9c542eba4edf8d061bd2e5007cf598625e112df, < 43fc0342bac1808fda2b76184e43414727111c6b; >= 8a02d70679fc1c434401863333c8ea7dbf201494, < e7d796fccdc8d17c2d21817ebe4c7bf5bbfe5433
LinuxLinux>= 5.15.106, < 5.15.107; >= 6.1.23, < 6.1.24; >= 6.2.10, < 6.2.11

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-54252?
In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.
How severe is CVE-2023-54252?
Severity scoring for CVE-2023-54252 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2023-54252?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-54252?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST