CVE-2023-53546Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx when mlx5_cmd_exec failed in mlx5dr_cmd_create_reformat_ctx, the memory pointed by 'in' is not released, which will cause memory leak. Move memory release after mlx5_cmd_exec.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.45.4.253+5
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux1d9186476e12c85dc81a0f01f5c614a9683af7f2800d8c96bf997da5eb76ccf8d88795c4231c83fb+6
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-98xf-q5m7-hgc7: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx when mlx5_cmd_ex2025-10-04
OSV
CVE-2023-53546: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx when mlx5_cmd_exec2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: net/mlx5: DR, fix memory leak in mlx5dr_cmd_create_reformat_ctx2025-10-04
Debian
CVE-2023-53546: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: D...2023