Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-54252

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 3.3

Описание

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

A memory leak was found in the Linux kernel's think-lmi driver for Lenovo ThinkStation systems. When parsing WMI strings, memory allocated for tlmi_setting is not properly freed, leading to a gradual memory leak over time. The fix ensures proper deallocation and renames the variable to avoid confusion.

Отчет

This flaw affects only Lenovo ThinkStation systems using the think-lmi driver and results in a minor memory leak during WMI string parsing operations. The leak accumulates slowly and does not present an immediate denial of service risk, making the practical security impact negligible.

Меры по смягчению последствий

To mitigate this issue, prevent the think-lmi module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2426099kernel: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings

3.3 Low

CVSS3

Связанные уязвимости

ubuntu
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

nvd
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

debian
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: p ...

github
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость функции tlmi_analyze() модуля drivers/platform/x86/think-lmi.c драйвера устройств X86 ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3