CVE-2023-53423

medium

Description

In the Linux kernel, the following vulnerability has been resolved: objtool: Fix memory leak in create_static_call_sections() strdup() allocates memory for key_name. We need to release the memory in the following error paths. Add free() to avoid memory leak.

References

https://git.kernel.org/stable/c/d131718d9c45d559951f57c4b88209ca407433c4

https://git.kernel.org/stable/c/a8f63d747bf7c983882a5ea7456a5f84ad3acad5

https://git.kernel.org/stable/c/a1368eaea058e451d20ea99ca27e72d9df0d16dd

https://git.kernel.org/stable/c/3da73f102309fe29150e5c35acd20dd82063ff67

https://git.kernel.org/stable/c/3a75866a5ceff5d4fdd5471e06c4c4d03e0298b3

Details

Source: Mitre, NVD

Published: 2025-09-18

Updated: 2025-09-19

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018