{"id":"DEBIAN-CVE-2023-52560","details":"In the Linux kernel, the following vulnerability has been resolved:  mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()  When CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y and CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y, the below memory leak is detected.  Since commit 9f86d624292c (\"mm/damon/vaddr-test: remove unnecessary variables\"), the damon_destroy_ctx() is removed, but still call damon_new_target() and damon_new_region(), the damon_region which is allocated by kmem_cache_alloc() in damon_new_region() and the damon_target which is allocated by kmalloc in damon_new_target() are not freed.  And the damon_region which is allocated in damon_new_region() in damon_set_regions() is also not freed.  So use damon_destroy_target to free all the damon_regions and damon_target.      unreferenced object 0xffff888107c9a940 (size 64):       comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)       hex dump (first 32 bytes):         00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b  ............kkkk         60 c7 9c 07 81 88 ff ff f8 cb 9c 07 81 88 ff ff  `...............       backtrace:         [\u003cffffffff817e0167\u003e] kmalloc_trace+0x27/0xa0         [\u003cffffffff819c11cf\u003e] damon_new_target+0x3f/0x1b0         [\u003cffffffff819c7d55\u003e] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0         [\u003cffffffff819c82be\u003e] damon_test_apply_three_regions1+0x21e/0x260         [\u003cffffffff829fce6a\u003e] kunit_generic_run_threadfn_adapter+0x4a/0x90         [\u003cffffffff81237cf6\u003e] kthread+0x2b6/0x380         [\u003cffffffff81097add\u003e] ret_from_fork+0x2d/0x70         [\u003cffffffff81003791\u003e] ret_from_fork_asm+0x11/0x20     unreferenced object 0xffff8881079cc740 (size 56):       comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)       hex dump (first 32 bytes):         05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00  ................         6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b  kkkkkkkk....kkkk       backtrace:         [\u003cffffffff819bc492\u003e] damon_new_region+0x22/0x1c0         [\u003cffffffff819c7d91\u003e] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0         [\u003cffffffff819c82be\u003e] damon_test_apply_three_regions1+0x21e/0x260         [\u003cffffffff829fce6a\u003e] kunit_generic_run_threadfn_adapter+0x4a/0x90         [\u003cffffffff81237cf6\u003e] kthread+0x2b6/0x380         [\u003cffffffff81097add\u003e] ret_from_fork+0x2d/0x70         [\u003cffffffff81003791\u003e] ret_from_fork_asm+0x11/0x20     unreferenced object 0xffff888107c9ac40 (size 64):       comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)       hex dump (first 32 bytes):         00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b  ............kkkk         a0 cc 9c 07 81 88 ff ff 78 a1 76 07 81 88 ff ff  ........x.v.....       backtrace:         [\u003cffffffff817e0167\u003e] kmalloc_trace+0x27/0xa0         [\u003cffffffff819c11cf\u003e] damon_new_target+0x3f/0x1b0         [\u003cffffffff819c7d55\u003e] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0         [\u003cffffffff819c851e\u003e] damon_test_apply_three_regions2+0x21e/0x260         [\u003cffffffff829fce6a\u003e] kunit_generic_run_threadfn_adapter+0x4a/0x90         [\u003cffffffff81237cf6\u003e] kthread+0x2b6/0x380         [\u003cffffffff81097add\u003e] ret_from_fork+0x2d/0x70         [\u003cffffffff81003791\u003e] ret_from_fork_asm+0x11/0x20     unreferenced object 0xffff8881079ccc80 (size 56):       comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)       hex dump (first 32 bytes):         05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00  ................         6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b  kkkkkkkk....kkkk       backtrace:         [\u003cffffffff819bc492\u003e] damon_new_region+0x22/0x1c0         [\u003cffffffff819c7d91\u003e] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0         [\u003cffffffff819c851e\u003e] damon_test_apply_three_regions2+0x21e/0x260         [\u003cffffffff829fce6a\u003e] kunit_generic_run_threadfn_adapter+0x4a/0x90         [\u003cffffffff81237cf6\u003e] kthread+0x2b6/0x380         [\u003cffffffff81097add\u003e] ret_from_fork+0x2d/0x70         [\u003cffff ---truncated---","modified":"2026-09-15T09:02:47.929875117Z","published":"2024-03-02T22:15:48.750Z","upstream":["CVE-2023-52560"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-52560"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.64-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52560.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52560.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52560.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}