CVE-2023-53423

MEDIUM

Linux Kernel 5.10-5.10.173 - Use-After-Free in create_static_call_sections

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: objtool: Fix memory leak in create_static_call_sections() strdup() allocates memory for key_name. We need to release the memory in the following error paths. Add free() to avoid memory leak.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (13)
Linux/Linux < 5.10
Linux/Linux 1e7e47883830aae5e8246a22ca2fc6883c61acdf - 3a75866a5ceff5d4fdd5471e06c4c4d03e0298b3
Linux/Linux 1e7e47883830aae5e8246a22ca2fc6883c61acdf - 3da73f102309fe29150e5c35acd20dd82063ff67
Linux/Linux 1e7e47883830aae5e8246a22ca2fc6883c61acdf - a1368eaea058e451d20ea99ca27e72d9df0d16dd
Linux/Linux 1e7e47883830aae5e8246a22ca2fc6883c61acdf - a8f63d747bf7c983882a5ea7456a5f84ad3acad5
Linux/Linux 1e7e47883830aae5e8246a22ca2fc6883c61acdf - d131718d9c45d559951f57c4b88209ca407433c4
Linux/Linux 5.10
Linux/Linux 5.10.173 - 5.10.*
Linux/Linux 5.15.100 - 5.15.*
Linux/Linux 6.1.18 - 6.1.*
... and 3 more
Published Sep 18, 2025
Tracked Since Feb 18, 2026