Wind River Support Network

HomeDefectsLIN1023-4099
Fixed

LIN1023-4099 : Security Advisory - linux - CVE-2023-52526

Created: Mar 2, 2024    Updated: Apr 3, 2024
Resolved Date: Apr 2, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.7
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

erofs: fix memory leak of LZMA global compressed deduplication

When stressing microLZMA EROFS images with the new global compressed
deduplication feature enabled (`-Ededupe`), I found some short-lived
temporary pages weren't properly released, which could slowly cause
unexpected OOMs hours later.

Let's fix it now (LZ4 and DEFLATE don't have this issue.)

CREATE(Triage):(User=admin) CVE-2023-52526 (https://nvd.nist.gov/vuln/detail/CVE-2023-52526)

CVEs


Live chat
Online