cbcvebase.
CVE-2023-53546
published 2025-10-04

CVE-2023-53546: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx when mlx5_cmd_exec failed…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx when mlx5_cmd_exec failed in mlx5dr_cmd_create_reformat_ctx, the memory pointed by 'in' is not released, which will cause memory leak. Move memory release after mlx5_cmd_exec.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 800d8c96bf997da5eb76ccf8d88795c4231c83fb800d8c96bf997da5eb76ccf8d88795c4231c83fb
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 165159854757dbae0dfd1812b27051da35aa6223165159854757dbae0dfd1812b27051da35aa6223
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 00cecb0a8f9e7a21754d5ad85813ab6b47b3308f00cecb0a8f9e7a21754d5ad85813ab6b47b3308f
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 3169c3854397f3070a63b1b772db16dcb8cba7b43169c3854397f3070a63b1b772db16dcb8cba7b4
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 622d71d99124e69f7bf2e2b7a89f5f444a24d235622d71d99124e69f7bf2e2b7a89f5f444a24d235
linuxlinux>= 1d9186476e12c85dc81a0f01f5c614a9683af7f2 < 5dd77585dd9d0e03dd1bceb95f0269a7eaf6b9365dd77585dd9d0e03dd1bceb95f0269a7eaf6b936
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.11 < 5.15.1265.15.126
linuxlinux_kernel>= 5.16 < 6.1.456.1.45
linuxlinux_kernel>= 5.4 < 5.4.2535.4.253
linuxlinux_kernel>= 5.5 < 5.10.1905.10.190
linuxlinux_kernel>= 6.2 < 6.4.106.4.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.