CVE-2023-54252
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54252 is a memory leak vulnerability in the Linux kernel's platform/x86: think-lmi driver, specifically in the code responsible for parsing ThinkStation WMI strings. The flaw was introduced by a prior commit that failed to free memory allocated from tlmi_setting, resulting in a resource leak. Affected kernel versions span multiple stable branches, including Linux 5.15.x before 5.15.107, 6.1.x before 6.1.24, and 6.2.x before 6.2.11, as well as specific commit ranges in the mainline tree (Feedly). The vulnerability was published on December 30, 2025, and carries an EPSS score of 0.0002 (very low probability of exploitation) (Feedly). No CVSS base score has been assigned at this time.

Technical details

The root cause is a missing memory deallocation (CWE-401: Missing Release of Memory after Effective Lifetime) in the think-lmi platform driver within the Linux kernel's x86 subsystem. When parsing WMI strings from ThinkStation firmware interfaces, a buffer allocated via tlmi_setting was not freed upon completion of the parsing routine, leading to a kernel memory leak. The fix also renames the affected variable to reduce confusion with a similarly named variable in the same function scope. Patches are available as stable commits across multiple kernel branches (Feedly).

Impact

The primary impact of this vulnerability is a kernel memory leak, which over time can degrade system availability by exhausting kernel memory resources on affected ThinkStation systems. There is no known path to privilege escalation, arbitrary code execution, or data exfiltration directly from this flaw. The confidentiality and integrity of the system are not directly affected; the risk is limited to availability degradation on systems running the vulnerable think-lmi kernel driver (Feedly).

Mitigation and workarounds

Apply the upstream Linux kernel patches that address this memory leak. Fixed versions include Linux 5.15.107, 6.1.24, and 6.2.11, as well as the corresponding mainline stable commits (43fc0342bac1, cccdb30935c8, 081da7b1c881, e7d796fccdc8) (Feedly). Users running affected ThinkStation systems should update to a patched kernel version through their distribution's standard update mechanism. No configuration-based workaround is known; upgrading the kernel is the recommended remediation.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management