Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53221— bpf: Fix memleak due to fentry attach failure

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于fentry附加失败时未释放分配的bpf trampoline映像,可能导致内存泄漏。

AI Predicted 5.0 Difficulty: Moderate EPSS 0.15% · P5

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux e21aa341785c679dd409c8cb71f864c00fe6c463< 20109ddd5bea2c24d790debf5d02584ef24c3f5e affected
e21aa341785c679dd409c8cb71f864c00fe6c463< f72c67d1a82dada7d6d504c806e111e913721a30 affected
e21aa341785c679dd409c8cb71f864c00fe6c463< 6aa27775db63ba8c7c73891c7dfb71ddc230c48d affected
e21aa341785c679dd409c8cb71f864c00fe6c463< 108598c39eefbedc9882273ac0df96127a629220 affected
e21d2b92354b3cd25dd774ebb0f0e52ff04a7861 affected
85d177f56e5256e14b74a65940f981f6e3e8bb32 affected
5.10.28< 5.11 affected
5.11.11< 5.12 affected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-53221

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
bpf: Fix memleak due to fentry attach failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix memleak due to fentry attach failure If it fails to attach fentry, the allocated bpf trampoline image will be left in the system. That can be verified by checking /proc/kallsyms. This meamleak can be verified by a simple bpf program as follows: SEC("fentry/trap_init") int fentry_run() { return 0; } It will fail to attach trap_init because this function is freed after kernel init, and then we can find the trampoline image is left in the system by checking /proc/kallsyms. $ tail /proc/kallsyms ffffffffc0613000 t bpf_trampoline_6442453466_1 [bpf] ffffffffc06c3000 t bpf_trampoline_6442453466_1 [bpf] $ bpftool btf dump file /sys/kernel/btf/vmlinux | grep "FUNC 'trap_init'" [2522] FUNC 'trap_init' type_id=119 linkage=static $ echo $((6442453466 & 0x7fffffff)) 2522 Note that there are two left bpf trampoline images, that is because the libbpf will fallback to raw tracepoint if -EINVAL is returned.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于fentry附加失败时未释放分配的bpf trampoline映像,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e21aa341785c679dd409c8cb71f864c00fe6c463 ~ 20109ddd5bea2c24d790debf5d02584ef24c3f5e -
Linux Linux 5.12 -

II. Public POCs for CVE-2023-53221

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53221

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-15 · 210 CVEs total

CVE-2022-50235 9.8 CRITICAL NFSD: Protect against send buffer overflow in NFSv2 READDIR
CVE-2022-50335 9.8 CRITICAL 9p: set req refcount to zero to avoid uninitialized usage
CVE-2023-53192 9.8 CRITICAL vxlan: Fix nexthop hash size
CVE-2023-53253 8.8 HIGH HID: nvidia-shield: Reference hid_device devm allocation of input_dev name
CVE-2023-53226 8.8 HIGH wifi: mwifiex: Fix OOB and integer underflow when rx packets
CVE-2022-50241 8.8 HIGH NFSD: fix use-after-free on source server when doing inter-server copy
CVE-2023-53194 8.4 HIGH fs/ntfs3: Add length check in indx_get_root
CVE-2023-53213 8.1 HIGH wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
CVE-2023-53186 8.1 HIGH skbuff: Fix a race between coalescing and releasing SKBs
CVE-2022-50310 7.8 HIGH ip6mr: fix UAF issue in ip6mr_sk_done() when addrconf_init_net() failed
CVE-2023-53254 7.8 HIGH cacheinfo: Fix shared_cpu_map to handle shared caches at different levels
CVE-2023-53252 7.8 HIGH Bluetooth: use RCU for hci_conn_params and iterate safely in hci_sync
CVE-2023-53170 7.8 HIGH net: dsa: Removed unneeded of_node_put in felix_parse_ports_node
CVE-2023-53176 7.8 HIGH serial: 8250: Reinit port->pm on port specific driver unbind
CVE-2023-53178 7.8 HIGH mm: fix zswap writeback race condition
CVE-2023-53179 7.8 HIGH netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c
CVE-2023-53184 7.8 HIGH arm64/sme: Set new vector length before reallocating
CVE-2022-50315 7.8 HIGH ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS
CVE-2023-53187 7.8 HIGH btrfs: fix use-after-free of new block group that became unused
CVE-2025-39800 7.8 HIGH btrfs: abort transaction on unexpected eb generation at btrfs_copy_root()

Showing top 20 of 210 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53221

No comments yet


Leave a comment