SB2025121019 - Memory leak in Linux kernel platform x86 driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53830)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the current_value_show() function in drivers/platform/x86/think-lmi.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5f99014c19fa50a5719c0bb78143282632675893
- https://git.kernel.org/stable/c/9071525bfcb1f5674117dbed3eca0cd7b122813b
- https://git.kernel.org/stable/c/a3c4c053014585dcf20f4df954791b74d8a8afcd
- https://git.kernel.org/stable/c/b9396d991abe8d1ac31a043274ab20b49f92c2e6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.107