CVE-2023-53190Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix memory leaks in error path The memory allocated by vxlan_vnigroup_init() is not freed in the error path, leading to memory leaks [1]. Fix by calling vxlan_vnigroup_uninit() in the error path. The leaks can be reproduced by annotating gro_cells_init() with ALLOW_ERROR_INJECTION() and then running: # echo "100" > /sys/kernel/debug/fail_function/probability # echo "1" > /sys/kernel/debug/fail_function/times # echo "g

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.186.0.19+2
Debianlinux/linux_kernel< 6.1.7-1+2
CVEListV5linux/linuxf9c4bb0b245cee35ef66f75bf409c9573d934cf975c1ab900f7cf0485f0be1607c79c55f51faaa90+3
debiandebian/linux< linux 6.1.7-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53190: In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix memory leaks in error path The memory allocated by vxlan_vnigroup_init(2025-09-15
GHSA
GHSA-62g8-53xp-7372: In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix memory leaks in error path The memory allocated by vxlan_vnigroup_ini2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: vxlan: Fix memory leaks in error path2025-09-15
Debian
CVE-2023-53190: linux - In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix ...2023
CVE-2023-53190 — Linux vulnerability | cvebase