SB2025120824 - Memory leak in Linux kernel coco sev-guest driver
Published: December 8, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53769)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the dec_payload(), verify_and_dec_payload() and handle_guest_request() functions in drivers/virt/coco/sev-guest/sev-guest.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4b69c63f716cfda38e1210e65b68f67f6cee2ddf
- https://git.kernel.org/stable/c/577a64725bfd77645986168e953d405067ee565b
- https://git.kernel.org/stable/c/965006103a14703cc42043bbf9b5e0cdf7a468ad
- https://git.kernel.org/stable/c/c27dafc4aa50a29ec927b3aa84ac7b430071f682
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.15