PT-2025-13313 · Linux+5 · Linux Kernel+5
Published
2023-02-02
·
Updated
2025-09-29
·
CVE-2023-52937
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak issue has been identified in the Linux kernel, specifically in the hv balloon component when using the
debugfs lookup() function. The issue arises because the result of debugfs lookup() must be followed by a call to dput() to prevent memory leaks over time. To simplify the process, the debugfs lookup and remove() function can be used instead, as it handles the necessary logic.Recommendations
To resolve the issue, consider updating the Linux kernel to a version that includes the fix for the memory leak in the hv balloon component.
As a temporary workaround, consider modifying the code to use
debugfs lookup and remove() instead of debugfs lookup() to prevent memory leaks.Exploit
Fix
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse