CVE-2023-53746
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/12/2025
Last modified:
08/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/vfio-ap: fix memory leak in vfio_ap device driver<br />
<br />
The device release callback function invoked to release the matrix device<br />
uses the dev_get_drvdata(device *dev) function to retrieve the<br />
pointer to the vfio_matrix_dev object in order to free its storage. The<br />
problem is, this object is not stored as drvdata with the device; since the<br />
kfree function will accept a NULL pointer, the memory for the<br />
vfio_matrix_dev object is never freed.<br />
<br />
Since the device being released is contained within the vfio_matrix_dev<br />
object, the container_of macro will be used to retrieve its pointer.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/5195de1d5f66b276683240a896783f7f43c4f664
- https://git.kernel.org/stable/c/6a40fda14b4be3e38f03cc42ffd4efbc64fb3e67
- https://git.kernel.org/stable/c/7b6a02f5bf15931464c79dfd487c57f76aae3496
- https://git.kernel.org/stable/c/8f8cf767589f2131ae5d40f3758429095c701c84
- https://git.kernel.org/stable/c/aa2bff25e9bb10c935c7ffe3d5f5975bdccb1749
- https://git.kernel.org/stable/c/ee17dea3072dec0bc34399a32fa884e26342e4ea



