CVE-2023-52653

MEDIUM

Linux Kernel 2.6.35-6.8.2 - Use-After-Free in SUNRPC gss_import_v2_context

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix a memleak in gss_import_v2_context The ctx->mech_used.data allocated by kmemdup is not freed in neither gss_import_v2_context nor it only caller gss_krb5_import_sec_context, which frees ctx on error. Thus, this patch reform the last call of gss_import_v2_context to the gss_krb5_import_ctx_v2, preventing the memleak while keepping the return formation.

Scores

CVSS v3 5.5
EPSS 0.0027
EPSS Percentile 19.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (11)
Linux/Linux < 2.6.35
Linux/Linux 2.6.35
Linux/Linux 47d84807762966c3611c38adecec6ea703ddda7a - 47ac11db93e74ac49cd6c3fc69bcbc5964c4a8b4
Linux/Linux 47d84807762966c3611c38adecec6ea703ddda7a - 99044c01ed5329e73651c054d8a4baacdbb1a27c
Linux/Linux 47d84807762966c3611c38adecec6ea703ddda7a - d111e30d9cd846bb368faf3637dc0f71fcbcf822
Linux/Linux 47d84807762966c3611c38adecec6ea703ddda7a - e67b652d8e8591d3b1e569dbcdfcee15993e91fa
Linux/Linux 6.6.23 - 6.6.*
Linux/Linux 6.7.11 - 6.7.*
Linux/Linux 6.8.2 - 6.8.*
Linux/Linux 6.9
... and 1 more
Published May 01, 2024
Tracked Since Feb 18, 2026