CVE-2023-52576: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: x86/mm, kexec, ima: Use memblock_free_late() from ima_free_kexec_buffer() The code calling ima_free_kexec_buffer() runs long after the memblock allocator has already been torn down, potentially resulting in a use after free in memblock_isolate_range(). With KASAN or KFENCE, this use after free will result in a BUG from the idle task, and a subsequent kernel panic. Switch ima_free_kexec_buffer() over to memblock_free_late() to avoid that bug.
Affected products
- Linux Linux Kernel: from 5.13, before 6.1.56 (fixed in 6.1.56); from 6.2, before 6.5.6 (fixed in 6.5.6); version 6.6 only
Published 2024-03-02. Last modified 2026-06-17.