CVE-2023-53266

MEDIUM

Linux Kernel 6.2-6.2.2 - Use-After-Free in ARM64 ACPI FFH Context Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Fix possible memory leak of ffh_ctxt Allocated 'ffh_ctxt' memory leak is possible if the SMCCC version and conduit checks fail and -EOPNOTSUPP is returned without freeing the allocated memory. Fix the same by moving the allocation after the SMCCC version and conduit checks.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (7)
Linux/Linux < 6.2
Linux/Linux 1d280ce099db396e092cac1aa9bf2ea8beee6d76 - 1b561d3949f8478c5403c9752b5533211a757226
Linux/Linux 1d280ce099db396e092cac1aa9bf2ea8beee6d76 - 7521da2eb42d65f89f511b7912d3757cf3d9168a
Linux/Linux 6.2
Linux/Linux 6.2.3 - 6.2.*
Linux/Linux 6.3
linux/linux_kernel 6.2 - 6.2.3
Published Sep 16, 2025
Tracked Since Feb 18, 2026