UBUNTU-CVE-2023-53708
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-53708
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects If a badly constructed firmware includes multiple `ACPI_TYPE_PACKAGE` objects while evaluating the AMD LPS0 _DSM, there will be a memory leak. Explicitly guard against this.
References: https://ubuntu.com/security/CVE-2023-53708, https://www.cve.org/CVERecord?id=CVE-2023-53708, https://git.kernel.org/linus/883cf0d4cf288313b71146ddebdf5d647b76c78b, https://git.kernel.org/stable/c/1ea7e47807279369c82718efd2677ea25c6579e3, https://git.kernel.org/stable/c/7b7964cd9db30bc84808a40d13a0633b4313f149, https://git.kernel.org/stable/c/883cf0d4cf288313b71146ddebdf5d647b76c78b, https://git.kernel.org/stable/c/9e8bbde9293151430884aed882a88eaa22298f72
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
