CVE-2023-53266: arm64: acpi: Fix possible memory leak of ffh_ctxt
In the Linux kernel, the following vulnerability has been resolved:
arm64: acpi: Fix possible memory leak of ffh_ctxt
Allocated 'ffh_ctxt' memory leak is possible if the SMCCC version
and conduit checks fail and -EOPNOTSUPP is returned without freeing the
allocated memory.
Fix the same by moving the allocation after the SMCCC version and
conduit checks.
Security readout for executives and security teams
Plain-English summary
CVE-2023-53266 is a Linux kernel memory leak in ARM64 ACPI handling. Under specific failed platform checks, allocated memory may not be freed. The main business risk is local availability impact, not data theft or privilege escalation based on the supplied sources.
Executive priority
Handle through normal kernel patch management, with higher priority for ARM64 production systems where downtime has operational impact. There is no supplied evidence of active exploitation or confidentiality impact.
Technical view
In ARM64 ACPI code, ffh_ctxt could be allocated before SMCCC version and conduit checks. If those checks failed and returned -EOPNOTSUPP, the allocation was not freed. The kernel fix moves allocation after those checks. The issue is classified as CWE-401 with CVSS 5.5.
Likely exposure
Exposure appears limited to ARM64 Linux systems running affected kernel versions in the supplied range, especially environments using ACPI-related firmware paths. The source bundle does not identify affected distributions, cloud images, appliances, or default configurations.
Exploitation context
The CVSS vector indicates local access with low privileges and no user interaction. The supplied sources do not report public exploitation, weaponized exploit availability, or CISA KEV listing. Treat it as a local denial-of-service risk unless vendor advisories say otherwise.
Researcher notes
The evidence is concise and kernel-focused. Version data in the bundle is limited, so avoid broad product claims. Research should map downstream distribution kernels to the upstream stable commits and confirm whether the relevant ARM64 ACPI path exists.
Mitigation direction
Update affected Linux kernels through the operating system or appliance vendor.
Confirm vendor updates include the referenced upstream stable commits.
Prioritize ARM64 systems where availability matters, including production edge and infrastructure hosts.
Monitor vendor advisories for distribution-specific package names and fixed versions.
Validation and detection
Inventory ARM64 Linux hosts and record exact kernel versions.
Check vendor changelogs for CVE-2023-53266 or the referenced commit hashes.
Validate scanner findings against the actual running kernel, not only installed packages.
Review availability monitoring for unexplained memory pressure on affected systems.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-401: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-401 · source CWE mapping
Missing Release of Memory after Effective Lifetime
Missing Release of Memory after Effective Lifetime represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.