vulnerability
Ubuntu: (CVE-2023-53746): linux vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Dec 8, 2025 | Dec 10, 2025 | Dec 11, 2025 |
Description
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function invoked to release the matrix device uses the dev_get_drvdata(device *dev) function to retrieve the pointer to the vfio_matrix_dev object in order to free its storage. The problem is, this object is not stored as drvdata with the device; since the kfree function will accept a NULL pointer, the memory for the vfio_matrix_dev object is never freed. Since the device being released is contained within the vfio_matrix_dev object, the container_of macro will be used to retrieve its pointer.
Solutions
References
- CVE-2023-53746
- https://attackerkb.com/topics/CVE-2023-53746
- URL-https://git.kernel.org/linus/8f8cf767589f2131ae5d40f3758429095c701c84
- URL-https://git.kernel.org/stable/c/5195de1d5f66b276683240a896783f7f43c4f664
- URL-https://git.kernel.org/stable/c/6a40fda14b4be3e38f03cc42ffd4efbc64fb3e67
- URL-https://git.kernel.org/stable/c/7b6a02f5bf15931464c79dfd487c57f76aae3496
- URL-https://git.kernel.org/stable/c/8f8cf767589f2131ae5d40f3758429095c701c84
- URL-https://git.kernel.org/stable/c/aa2bff25e9bb10c935c7ffe3d5f5975bdccb1749
- URL-https://git.kernel.org/stable/c/ee17dea3072dec0bc34399a32fa884e26342e4ea
- URL-https://www.cve.org/CVERecord?id=CVE-2023-53746
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.