PT-2025-38462 · Linux+4 · Linux Kernel+4

Published

2023-01-05

·

Updated

2025-10-23

·

CVE-2023-53443

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A reference count leak was resolved in the arizona clock driver within the Linux kernel. The arizona clk32k enable() function incorrectly used pm runtime get sync(), which increases the reference count even when an error occurs. This was corrected by using pm runtime resume and get().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-12975
CESA-2023_7077
CVE-2023-53443
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse