CVE-2023-53408

Updated: 2026-02-27 02:22:36.472639

Description:

In the Linux kernel, the following vulnerability has been resolved: trace/blktrace: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-10-01 13:53:57 This issue is limited to the optional blktrace path in debugfs and is reachable only locally when de...
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-12-18 19:39:11
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-12-18 19:39:10
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-12-18 19:39:11
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-12-18 19:39:10
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Ignored 2026-01-16 16:41:41 This issue is confined to the optional blktrace diagnostics path and requires local access plus an e...
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Ignored 2026-01-16 16:41:07 This issue is confined to the optional blktrace diagnostics path and requires local access plus an e...
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Ignored 2026-01-16 16:41:07 This issue is confined to the optional blktrace diagnostics path and requires local access plus an e...