Bug 1224689 (CVE-2023-52684)

Summary: VUL-0: CVE-2023-52684: kernel: firmware: qcom: qseecom: fix memory leaks in error paths
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: gabriele.sonnu, jlee
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/406390/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-52684:5.5:(AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description SMASH SMASH 2024-05-20 16:06:51 UTC
In the Linux kernel, the following vulnerability has been resolved:

firmware: qcom: qseecom: fix memory leaks in error paths

Fix instances of returning error codes directly instead of jumping to
the relevant labels where memory allocated for the SCM calls would be
freed.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52684
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2023/CVE-2023-52684.mbox
https://git.kernel.org/stable/c/85fdbf6840455be64eac16bdfe0df3368ee3d0f0
https://git.kernel.org/stable/c/6c57d7b593c4a4e60db65d5ce0fe1d9f79ccbe9b
https://www.cve.org/CVERecord?id=CVE-2023-52684
https://bugzilla.redhat.com/show_bug.cgi?id=2281315
Comment 1 Joey Lee 2024-05-21 07:12:05 UTC
https://www.suse.com/security/cve/CVE-2023-52684.html
cvss 5.5
Comment 3 Joey Lee 2024-05-24 06:47:28 UTC
Nothing to be done.
Comment 4 Andrea Mattiazzo 2024-06-07 12:22:19 UTC
All done, closing.