CVE-2023-53375
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53375 is a memory leak vulnerability discovered in the Linux kernel's tracing subsystem. The issue was identified and disclosed on September 18, 2025, affecting the error logging functionality of tracing instances. When a tracing instance is removed, the error messages that hold errors occurring in the instance are not properly freed, leading to memory leaks (NVD Database).

Technical details

The vulnerability occurs in the tracing subsystem of the Linux kernel when handling error logs for tracing instances. When creating a tracing instance and triggering an error condition (such as using an invalid histogram configuration), the system allocates memory to store error messages. However, these allocations are not properly freed when the tracing instance is removed, resulting in memory leaks of varying sizes (192 bytes and 32 bytes have been documented in test cases). The issue can be reproduced by creating a tracing instance, generating an error, and then removing the instance (NVD Database).

Impact

The primary impact of this vulnerability is resource exhaustion through memory leaks. When exploited, the system gradually loses available memory as tracing instances are created and removed, potentially leading to degraded system performance over time. While the immediate impact per instance is relatively small (documented leaks of 192 and 32 bytes), repeated exploitation could accumulate to cause significant memory consumption (NVD Database).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-modules-internal
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management