SB2025100816 - Memory leak in Linux kernel perf
Published: October 8, 2025 Updated: October 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53649)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the evlist__free_syscall_tp_fields() function in tools/perf/builtin-trace.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/27f396f64537b1ae48d0644d7cbf0d250b3c0b33
- https://git.kernel.org/stable/c/62dd514c34be63d3d5cae1f52a7e8b96c6dd6630
- https://git.kernel.org/stable/c/7962ef13651a9163f07b530607392ea123482e8a
- https://git.kernel.org/stable/c/c3bc668581e71e7c3bc7eb1d647f25f8db222163
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.132