CVE-2023-52663

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2024
Last modified:
07/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe()<br /> <br /> Driver uses kasprintf() to initialize fw_{code,data}_bin members of<br /> struct acp_dev_data, but kfree() is never called to deallocate the<br /> memory, which results in a memory leak.<br /> <br /> Fix the issue by switching to devm_kasprintf(). Additionally, ensure the<br /> allocation was successful by checking the pointer validity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6 (including) 6.6.23 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.11 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.8.2 (excluding)