PT-2025-41093 · Linux+3 · Linux Kernel+3

Publicado

2022-05-10

·

Atualizado

2025-11-28

·

CVE-2023-53649

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a memory leak in the perf trace functionality. Specifically, the evsel->priv area was not consistently freed, leading to memory leaks detected during testing with AddressSanitizer. The issue stemmed from incorrect conditional freeing logic in the evsel trace new and related functions, such as evsel syscall tp and evsel init raw syscall tp. The fix ensures that evsel->priv is freed when it is set, regardless of the tp system value. The leak was identified during testing with perf trace sleep 1.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Improper Initialization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2026-04119
CESA-2022_1988
CVE-2023-53649
RHSA-2022:1988
RHSA-2022_1988
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Produtos afetados

Centos
Linux Kernel
Red Hat
Suse