cbcvebase.
CVE-2023-53696
published 2025-10-22

CVE-2023-53696: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in qla2x00_probe_one() There is a memory leak reported by…

PriorityP418low5.5
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in qla2x00_probe_one() There is a memory leak reported by kmemleak: unreferenced object 0xffffc900003f0000 (size 12288): comm "modprobe", pid 19117, jiffies 4299751452 (age 42490.264s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __vmalloc_node_range+0xe56/0x1110 [] __vmalloc_node+0xbd/0x150 [] vmalloc+0x25/0x30 [] qla2x00_create_host+0x7a0/0xe30 [qla2xxx] [] qla2x00_probe_one+0x2eb8/0xd160 [qla2xxx] [] local_pci_probe+0xeb/0x1a0 The root cause is traced to an error-handling path in qla2x00_probe_one() when the adapter "base_vha" initialize failed. The fab_scan_rp "scan.l" is used to record the port information and it is allocated in qla2x00_create_host(). However, it is not released in the error handling path "probe_failed". Fix this by freeing the memory of "scan.l" when an error occurs in the adapter initialization process.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < ae73c4dd48f2c79d515d509a0cbe9efb0a197f44ae73c4dd48f2c79d515d509a0cbe9efb0a197f44
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 44374911ac63f769c442f56fdfadea673c5f442544374911ac63f769c442f56fdfadea673c5f4425
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 582e35e97318ccd9c81774bac08938291679525f582e35e97318ccd9c81774bac08938291679525f
linuxlinux>= a4239945b8ad112fb914d0605c8f6c5fd3330f61 < 85ade4010e13ef152ea925c74d94253db92e542885ade4010e13ef152ea925c74d94253db92e5428
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 4.16.0 < 5.15.1075.15.107
linuxlinux_kernel>= 5.16.0 < 6.1.246.1.24
linuxlinux_kernel>= 6.2.0 < 6.2.116.2.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.