Memory leak in Linux kernel - CVE-2023-52560

 

Memory leak in Linux kernel - CVE-2023-52560

Published: May 30, 2024 / Updated: May 14, 2025


Vulnerability identifier: #VU90024
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-52560
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the damon_do_test_apply_three_regions() function in mm/damon/vaddr-test.h. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Oracle Linux
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Anolis OS
openEuler
IBM Integrated Analytics System
IBM QRadar Network Packet Capture
IBM Storage Scale System
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Storage Copy Data Management
Technical Support Appliance
Storage Protect Plus Server
Guardium Data Protection
Red Hat OpenShift Dev Spaces
OpenShift Logging
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-debug-devel
kernel-debug-modules
kernel-debug-modules-extra
kernel-debug-core
kernel-debug
kernel-cross-headers
kernel-core
bpftool
kernel
kernel-modules
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-headers
kernel-devel
kernel-tools-debuginfo
bpftool-debuginfo
perf-debuginfo
kernel-tools-devel
kernel-source
kernel-debugsource
kernel-debuginfo
python3-perf-debuginfo

How to mitigate CVE-2023-52560

Install update from vendor's website.

Linux kernel - addressed in versions 6.1.56, 6.5.6, 6.6
IBM Integrated Analytics System - update to 1.0.31.0
IBM Storage Scale System - update to 6.1.9.8
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Storage Copy Data Management - update to 2.2.24.1
Technical Support Appliance - update to 3.0.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.32, 4.14.33, 4.15.21
kernel (Red Hat package) - update to 4.18.0-553.8.1.el8_10
kernel-rt (Red Hat package) - update to 4.18.0-553.8.1.rt7.349.el8_10
kernel-debug-devel - update to 4.18.0-553.8.1.0.1
kernel-debug-modules - update to 4.18.0-553.8.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-debug-core - update to 4.18.0-553.8.1.0.1
kernel-debug - update to 4.18.0-553.8.1.0.1
kernel-cross-headers - update to 4.18.0-553.8.1.0.1
kernel-core - update to 4.18.0-553.8.1.0.1
bpftool - update to 4.18.0-553.8.1.0.1
kernel - update to 4.18.0-553.8.1.0.1
kernel-modules - update to 4.18.0-553.8.1.0.1
kernel-doc - update to 4.18.0-553.8.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.8.1.0.1
python3-perf - update to 4.18.0-553.8.1.0.1
perf - update to 4.18.0-553.8.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.8.1.0.1
kernel-tools-libs - update to 4.18.0-553.8.1.0.1
kernel-tools - update to 4.18.0-553.8.1.0.1
kernel-modules-extra - update to 4.18.0-553.8.1.0.1
kernel-headers - update to 4.18.0-553.8.1.0.1
kernel-devel - update to 4.18.0-553.8.1.0.1
OpenShift Logging - update to 5.6.21
kernel-tools-debuginfo - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
bpftool-debuginfo - update to 5.10.0-60.134.0.161
kernel-devel - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
perf-debuginfo - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel-tools-devel - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel-source - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel-debugsource - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
perf - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
bpftool - update to 5.10.0-60.134.0.161
kernel-tools - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel-debuginfo - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
python3-perf-debuginfo - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
python3-perf - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
kernel-headers - addressed in versions 5.10.0-60.134.0.161, 5.10.0-136.72.0.152, 5.10.0-153.51.0.129, 5.10.0-196.0.0.109
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 10
Storage Protect Plus Server - update to 10.1.16.3
Guardium Data Protection - addressed in versions 12.0p35, 12.0p115
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
IBM Business Automation Workflow - update to 24.0.0-IF002

External References

Related Security Bulletins