PT-2025-13313 · Linux+5 · Linux Kernel+5

Published

2023-02-02

·

Updated

2025-09-29

·

CVE-2023-52937

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the hv balloon component when using the debugfs lookup() function. The issue arises because the result of debugfs lookup() must be followed by a call to dput() to prevent memory leaks over time. To simplify the process, the debugfs lookup and remove() function can be used instead, as it handles the necessary logic.
Recommendations To resolve the issue, consider updating the Linux kernel to a version that includes the fix for the memory leak in the hv balloon component. As a temporary workaround, consider modifying the code to use debugfs lookup and remove() instead of debugfs lookup() to prevent memory leaks.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06259
CESA-2023_7077
CVE-2023-52937
OPENSUSE-SU-2025_01620-1
OPENSUSE-SU-2025_01640-1
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:01620-1
SUSE-SU-2025:01640-1
SUSE-SU-2025_01620-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse