Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-52520
HistoryMar 02, 2024 - 12:00 a.m.

CVE-2023-52520

2024-03-0200:00:00
ubuntu.com
ubuntu.com
7
linux kernel
vulnerability fix
reference leak
platform/x86
think-lmi
kset_find_obj
kobject_put
setting name validation

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix reference leak If a duplicate attribute is
found using kset_find_obj(), a reference to that attribute is returned
which needs to be disposed accordingly using kobject_put(). Move the
setting name validation into a separate function to allow for this change
without having to duplicate the cleanup code for this setting. As a side
note, a very similar bug was fixed in commit 7295a996fdab (“platform/x86:
dell-sysman: Fix reference leak”), so it seems that the bug was copied from
that driver. Compile-tested only.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlinux< 5.15.0-94.104UNKNOWN
ubuntu23.10noarchlinux< 6.5.0-17.17UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1053.58UNKNOWN
ubuntu23.10noarchlinux-aws< 6.5.0-1013.13UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1053.58~20.04.1UNKNOWN
ubuntu22.04noarchlinux-aws-6.5< 6.5.0-1013.13~22.04.1UNKNOWN
ubuntu22.04noarchlinux-azure< 5.15.0-1056.64UNKNOWN
ubuntu23.10noarchlinux-azure< 6.5.0-1013.13UNKNOWN
ubuntu20.04noarchlinux-azure-5.15< 5.15.0-1056.64~20.04.1UNKNOWN
ubuntu22.04noarchlinux-azure-6.5< 6.5.0-1013.13~22.04.1UNKNOWN
Rows per page:
1-10 of 451

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%