CVE-2023-53611
Linux Kernel vulnerability analysis and mitigation

Overview

A memory leak vulnerability was discovered in the Linux kernel's IPMI subsystem, specifically in the try_smi_init() function. The vulnerability was assigned CVE-2023-53611 and was disclosed on October 4, 2025. The issue affects the ipmi_si driver in the Linux kernel (NVD).

Technical details

The vulnerability occurs when an error happens before handlers registration and after allocating new_smi->si_sm. In this scenario, the variable wouldn't be freed in the error handling path since shutdown_smi() hadn't been registered yet. The issue was detected by Kmemleak, which reported an unreferenced object of size 1024 bytes in the modprobe process. The vulnerability has been assigned a CVSS v3.1 score of 5.5 (Low) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (RedHat).

Impact

The vulnerability results in a memory leak in the Linux kernel's IPMI subsystem. While the immediate impact is resource consumption through memory leaks, the long-term effects could include system performance degradation if the leak occurs repeatedly (NVD).

Mitigation and workarounds

The vulnerability has been fixed by adding a kfree() call in the error handling path in try_smi_init(). Red Hat has marked this fix as deferred for Red Hat Enterprise Linux 8 and 9, including their RT (Real-Time) kernel variants (RedHat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-oracle
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management