CVE-2023-53746: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function invoked to release the matrix device uses the dev_get_drvdata(device *dev) function to retrieve the pointer to the vfio_matrix_dev object in order to free its storage. The problem is, this object is not stored as drvdata with the device; since the kfree function will accept a NULL pointer, the memory for the vfio_matrix_dev object is never freed. Since the device being released is contained within the vfio_matrix_dev object, the container_of macro will be used to retrieve its pointer.
Affected products
- Linux Linux: from 4.20, before 5.4.240 (fixed in 5.4.240); from 5.5, before 5.10.177 (fixed in 5.10.177); from 5.11, before 5.15.106 (fixed in 5.15.106); from 5.16, before 6.1.23 (fixed in 6.1.23); from 6.2, before 6.2.10 (fixed in 6.2.10)
Published 2025-12-08. Last modified 2026-06-17.