CVE-2023-52730 affects the Linux kernel MMC/SDIO subsystem, where failures in sdio_add_func() or sdio_init_func() could leave device-tree node and device references unreleased. Because an SDIO function was not marked present during those error paths, cleanup could skip of_node_put() and put_device(), causing memory and resource leaks observable through fault-injection testing. The flaw has local availability implications and was introduced in kernel 2.6.33.
Upstream corrected the cleanup flow by ensuring device-tree and device references are always released while retaining conditional device deletion, and by relocating reference acquisition and release to balance get_device() and put_device() operations. Fixes are available in stable kernels 4.14.306, 4.19.273, 5.4.232, 5.10.169, 5.15.95, 6.1.13, and 6.2, and Red Hat issued updates for RHEL 8, RHEL 8 kernel-rt, RHEL 9, and RHEL 9.4 EUS; RHEL 9 kernel-rt was listed as affected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 for the RHEL 8 kernel and RHSA-2024:5102 for the RHEL 8 kernel-rt, addressing CVE-2023-52730.
Red Hat published its record for CVE-2023-52730, describing a low-severity Linux kernel MMC/SDIO resource-leak vulnerability. Red Hat assigned a CVSS v3.1 score of 4.4.
Red Hat released RHSA-2025:15016 to address CVE-2023-52730 in the RHEL 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to fix CVE-2023-52730 in the RHEL 9 kernel.
The resource-leak issue was fixed in Linux stable releases 4.14.306, 4.19.273, 5.4.232, 5.10.169, 5.15.95, 6.1.13, and 6.2. The changes ensure applicable of_node_put() and put_device() cleanup calls occur even when the SDIO function is not present.
The MMC/SDIO error-path flaw was introduced by commit 3d10a1ba0d37 in Linux kernel 2.6.33. Failed sdio_add_func() or sdio_init_func() operations could leave device-tree-node and device references unreleased.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.