PT-2025-13335 · Linux+3 · Linux Kernel+3

Published

2023-01-17

·

Updated

2025-06-17

·

CVE-2023-52989

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 2.6.33 and later
Description A memory leak issue was found in the Linux FireWire subsystem related to the payload of request subaction to IEC 61883-1 FCP region. This issue occurred due to a use-after-free problem, where data of the payload was released before user space listeners could access it. The problem was caused by the subsystem allowing multiple user space listeners to the region while the payload data was likely released before the listeners could execute read(2) to access it. The issue was resolved by duplicating the payload object in kernel space for each listener and ensuring its proper release.
Recommendations For Linux kernel versions 2.6.33 and later, apply the patch that fixes the memory leak issue by explicitly releasing the payload object in the ioctl send response() function. This can be achieved by updating to a version of the Linux kernel that includes the commit 281e20323ab7 ("firewire: core: fix use-after-free regression in FCP handler"). As a temporary workaround, consider restricting access to the FireWire subsystem to minimize the risk of exploitation.

Exploit

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06270
CVE-2023-52989
OPENSUSE-SU-2025_1195-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse