Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53271

20
FAUCET Score

CVE-2023-53271 is a memory leak vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem, specifically within the ubi_resize_volume() function. This flaw, categorized as CWE-401 (Improper Release of Memory Before Removing Last Reference), occurs due to a mismatch in memory allocation and deallocation routines, leading to unreferenced objects. With a CVSS v3.1 score of 5.5 (MEDIUM), it has a local attack vector, low attack complexity, and primarily impacts availability (A:H) without affecting confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.9, < 4.14.308CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.235CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.173CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.100CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 28th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53271Low

kernel: ubi: Fix unreferenced object reported by kmemleak in ubi_resize_volume()

Sep 16, 2025

References

git.kernel.org / stable/c/07b60f7452d2fa731737552937cb81821919f874
Patch
git.kernel.org / stable/c/09780a44093b53f9cbca76246af2e4ff0884e512
Patch
git.kernel.org / stable/c/1e591ea072df7211f64542a09482b5f81cb3ad27
Patch
git.kernel.org / stable/c/26ec2d66aecab8ff997b912c20247fedba4f5740
Patch
git.kernel.org / stable/c/27b760b81951d8d5e5c952a696af8574052b0709
Patch
git.kernel.org / stable/c/31d60afe2cc2b712dbefcaab6b7d6a47036f844e
Patch
git.kernel.org / stable/c/5c0c81a313492b83bd0c038b8839b0e04eb87563
Patch
git.kernel.org / stable/c/95a72417dd13ebcdcb1bd0c5d4d15f7c5bfbb288
Patch