Bug 1240321 (CVE-2023-52936) - VUL-0: CVE-2023-52936: kernel: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup()
Summary: VUL-0: CVE-2023-52936: kernel: kernel/irq/irqdomain.c: fix memory leak with u...
Status: RESOLVED FIXED
Alias: CVE-2023-52936
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/447430/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-52936:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2025-03-28 14:10 UTC by SMASH SMASH
Modified: 2025-07-03 11:07 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2025-03-28 14:10:54 UTC
In the Linux kernel, the following vulnerability has been resolved:

kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup()

When calling debugfs_lookup() the result must have dput() called on it,
otherwise the memory will leak over time.  To make things simpler, just
call debugfs_lookup_and_remove() instead which handles all of the logic
at once.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52936
https://www.cve.org/CVERecord?id=CVE-2023-52936
https://git.kernel.org/stable/c/066ecbf1a53eb0b92b10c8df7808666be6ea5681
https://git.kernel.org/stable/c/cf1c917bf1c761a557b26410024e90057646c049
https://git.kernel.org/stable/c/d83d7ed260283560700d4034a80baad46620481b
https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2023/CVE-2023-52936.mbox
https://bugzilla.redhat.com/show_bug.cgi?id=2355520
Comment 5 Maintenance Automation 2025-05-21 12:30:32 UTC
SUSE-SU-2025:01640-1: An update that solves 40 vulnerabilities and has seven security fixes can now be installed.

URL: https://www.suse.com/support/update/announcement/2025/suse-su-202501640-1
Category: security (important)
Bug References: 1054914, 1206843, 1210409, 1225903, 1229361, 1229621, 1230764, 1231103, 1231910, 1236777, 1237981, 1238032, 1238471, 1238512, 1238747, 1238865, 1239061, 1239684, 1239968, 1240209, 1240211, 1240214, 1240228, 1240230, 1240246, 1240248, 1240269, 1240271, 1240274, 1240285, 1240295, 1240306, 1240314, 1240315, 1240321, 1240747, 1240835, 1241280, 1241371, 1241421, 1241433, 1241541, 1241625, 1241648, 1242284, 1242493, 1242778
CVE References: CVE-2021-47671, CVE-2022-48933, CVE-2022-49110, CVE-2022-49139, CVE-2022-49741, CVE-2022-49745, CVE-2022-49767, CVE-2023-52928, CVE-2023-52931, CVE-2023-52936, CVE-2023-52937, CVE-2023-52938, CVE-2023-52981, CVE-2023-52982, CVE-2023-52986, CVE-2023-52994, CVE-2023-53001, CVE-2023-53002, CVE-2023-53009, CVE-2023-53014, CVE-2023-53018, CVE-2023-53031, CVE-2023-53051, CVE-2024-42307, CVE-2024-46763, CVE-2024-46865, CVE-2024-50038, CVE-2025-21726, CVE-2025-21785, CVE-2025-21791, CVE-2025-21812, CVE-2025-21839, CVE-2025-22004, CVE-2025-22020, CVE-2025-22045, CVE-2025-22055, CVE-2025-22097, CVE-2025-2312, CVE-2025-23138, CVE-2025-39735
Maintenance Incident: [SUSE:Maintenance:38727](https://smelt.suse.de/incident/38727/)
Sources used:
openSUSE Leap 15.5 (src):
 kernel-syms-rt-5.14.21-150500.13.94.1, kernel-source-rt-5.14.21-150500.13.94.1
SUSE Linux Enterprise Micro 5.5 (src):
 kernel-source-rt-5.14.21-150500.13.94.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Maintenance Automation 2025-05-21 12:32:15 UTC
SUSE-SU-2025:01620-1: An update that solves 40 vulnerabilities and has seven security fixes can now be installed.

URL: https://www.suse.com/support/update/announcement/2025/suse-su-202501620-1
Category: security (important)
Bug References: 1054914, 1206843, 1210409, 1225903, 1229361, 1229621, 1230764, 1231103, 1231910, 1236777, 1237981, 1238032, 1238471, 1238512, 1238747, 1238865, 1239061, 1239684, 1239968, 1240209, 1240211, 1240214, 1240228, 1240230, 1240246, 1240248, 1240269, 1240271, 1240274, 1240285, 1240295, 1240306, 1240314, 1240315, 1240321, 1240747, 1240835, 1241280, 1241371, 1241421, 1241433, 1241541, 1241625, 1241648, 1242284, 1242493, 1242778
CVE References: CVE-2021-47671, CVE-2022-48933, CVE-2022-49110, CVE-2022-49139, CVE-2022-49741, CVE-2022-49745, CVE-2022-49767, CVE-2023-52928, CVE-2023-52931, CVE-2023-52936, CVE-2023-52937, CVE-2023-52938, CVE-2023-52981, CVE-2023-52982, CVE-2023-52986, CVE-2023-52994, CVE-2023-53001, CVE-2023-53002, CVE-2023-53009, CVE-2023-53014, CVE-2023-53018, CVE-2023-53031, CVE-2023-53051, CVE-2024-42307, CVE-2024-46763, CVE-2024-46865, CVE-2024-50038, CVE-2025-21726, CVE-2025-21785, CVE-2025-21791, CVE-2025-21812, CVE-2025-21839, CVE-2025-22004, CVE-2025-22020, CVE-2025-22045, CVE-2025-22055, CVE-2025-22097, CVE-2025-2312, CVE-2025-23138, CVE-2025-39735
Maintenance Incident: [SUSE:Maintenance:38685](https://smelt.suse.de/incident/38685/)
Sources used:
SUSE Linux Enterprise Live Patching 15-SP5 (src):
 kernel-livepatch-SLE15-SP5_Update_26-1-150500.11.3.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-obs-build-5.14.21-150500.55.103.1, kernel-syms-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-obs-build-5.14.21-150500.55.103.1, kernel-syms-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1
SUSE Linux Enterprise Server 15 SP5 LTSS (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-obs-build-5.14.21-150500.55.103.1, kernel-syms-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-obs-build-5.14.21-150500.55.103.1, kernel-syms-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1
openSUSE Leap 15.5 (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-obs-qa-5.14.21-150500.55.103.1, kernel-obs-build-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1, kernel-syms-5.14.21-150500.55.103.1, kernel-livepatch-SLE15-SP5_Update_26-1-150500.11.3.1
SUSE Linux Enterprise Micro 5.5 (src):
 kernel-source-5.14.21-150500.55.103.1, kernel-default-base-5.14.21-150500.55.103.1.150500.6.49.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.