CVE-2023-52662: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: fix a memleak in vmwgmridmangetnode
The Linux kernel CVE team has assigned CVE-2023-52662 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051740-CVE-2023-52662-1536@gregkh/T
Other sources
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: fix a memleak in vmwgmridmangetnode
When idaallocmax fails, resources allocated before should be freed, including res allocated by kmalloc and ttmresourceinit.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.153 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.83 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.23 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.11 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52662?
CVE-2023-52662 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2023-52662?
To fix CVE-2023-52662, update the Linux kernel to a patched version such as 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, or 6.9.
What versions of the Linux kernel are affected by CVE-2023-52662?
CVE-2023-52662 affects specific versions of the Linux kernel from 5.14 to 5.15.153 and other versions from 5.16 to 6.1.83.
Does CVE-2023-52662 involve a memory leak?
Yes, CVE-2023-52662 addresses a memory leak issue in the DRM vmwgfx module of the Linux kernel.
Is CVE-2023-52662 specific to any Linux distributions?
CVE-2023-52662 is relevant to Linux distributions using affected kernel versions, particularly those maintained by Red Hat and Debian.