#VU89981 Memory leak in Linux kernel


Published: 2024-05-30

Vulnerability identifier: #VU89981

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52690

CWE-ID: CWE-401

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the scom_debug_init_one() function in arch/powerpc/platforms/powernv/opal-xscom.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/f84c1446daa552e9699da8d1f8375eac0f65edc7
http://git.kernel.org/stable/c/1eefa93faf69188540b08b024794fa90b1d82e8b
http://git.kernel.org/stable/c/2a82c4439b903639e0a1f21990cd399fb0a49c19
http://git.kernel.org/stable/c/ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2
http://git.kernel.org/stable/c/dd8422ff271c22058560832fc3006324ded895a9
http://git.kernel.org/stable/c/a9c05cbb6644a2103c75b6906e9dafb9981ebd13
http://git.kernel.org/stable/c/9a260f2dd827bbc82cc60eb4f4d8c22707d80742


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability