SB2025091941 - Memory leak in Linux kernel base driver
Published: September 19, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53390)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the late_initcall() function in drivers/base/dd.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/36c893d3a759ae7c91ee7d4871ebfc7504f08c40
- https://git.kernel.org/stable/c/5a7a9efdb193d3c8a35821548a8e99612c358828
- https://git.kernel.org/stable/c/7f1e53f88e8babf293ec052b70aa9d2a3554360c
- https://git.kernel.org/stable/c/8e47e2bf78812adbd73c45c941d3c51add30b58d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.5