VYPR
Unrated severityNVD Advisory· Published Dec 30, 2025· Updated Apr 15, 2026

CVE-2023-54252

CVE-2023-54252

Description

In the Linux kernel, the following vulnerability has been resolved:

platform/x86: think-lmi: Fix memory leaks when parsing ThinkStation WMI strings

My previous commit introduced a memory leak where the item allocated from tlmi_setting was not freed. This commit also renames it to avoid confusion with the similarly name variable in the same function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A memory leak in the Linux kernel's think-lmi driver when parsing ThinkStation WMI strings can lead to resource exhaustion.

Vulnerability

Overview

CVE-2023-54252 is a memory leak vulnerability in the Linux kernel's think-lmi driver, specifically in the code that parses WMI (Windows Management Instrumentation) strings for ThinkStation systems. The issue was introduced by a previous commit that allocated memory via tlmi_setting but failed to free it, resulting in a memory leak. The fix renames the variable to avoid confusion with a similarly named variable in the same function and ensures proper deallocation [1][2].

Exploitation

This vulnerability is local in nature, requiring an attacker to have the ability to trigger the parsing of WMI strings on a system using the think-lmi driver. No special privileges beyond local access are needed, as the driver is part of the kernel and can be triggered by normal system operations or by an attacker with local user access. The attack surface is limited to systems with Lenovo ThinkStation hardware that utilize the think-lmi driver.

Impact

An attacker who can repeatedly trigger the vulnerable code path can cause a gradual memory leak, potentially leading to system instability or denial of service (DoS) due to memory exhaustion. The impact is primarily availability, as the leak does not directly allow privilege escalation or data corruption.

Mitigation

The vulnerability is fixed in the Linux kernel by commits that properly free the allocated memory. Users should apply the latest kernel updates from their distribution. No workaround is available other than updating the kernel.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

4

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

4

News mentions

0

No linked articles in our index yet.