cbcvebase.
CVE-2023-54024
published 2025-12-24

CVE-2023-54024: In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy target device if coalesced MMIO unregistration fails Destroy and free the…

PriorityP420low5.5
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy target device if coalesced MMIO unregistration fails Destroy and free the target coalesced MMIO device if unregistering said device fails. As clearly noted in the code, kvm_io_bus_unregister_dev() does not destroy the target device. BUG: memory leak unreferenced object 0xffff888112a54880 (size 64): comm "syz-executor.2", pid 5258, jiffies 4297861402 (age 14.129s) hex dump (first 32 bytes): 38 c7 67 15 00 c9 ff ff 38 c7 67 15 00 c9 ff ff 8.g.....8.g..... e0 c7 e1 83 ff ff ff ff 00 30 67 15 00 c9 ff ff .........0g..... backtrace: [] kmalloc include/linux/slab.h:556 [inline] [] kzalloc include/linux/slab.h:690 [inline] [] kvm_vm_ioctl_register_coalesced_mmio+0x8e/0x3d0 arch/x86/kvm/../../../virt/kvm/coalesced_mmio.c:150 [] kvm_vm_ioctl+0x47d/0x1600 arch/x86/kvm/../../../virt/kvm/kvm_main.c:3323 [] vfs_ioctl fs/ioctl.c:46 [inline] [] file_ioctl fs/ioctl.c:509 [inline] [] do_vfs_ioctl+0xbab/0x1160 fs/ioctl.c:696 [] ksys_ioctl+0x76/0xa0 fs/ioctl.c:713 [] __do_sys_ioctl fs/ioctl.c:720 [inline] [] __se_sys_ioctl fs/ioctl.c:718 [inline] [] __x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:718 [] do_syscall_64+0x9f/0x4e0 arch/x86/entry/common.c:290 [] entry_SYSCALL_64_after_hwframe+0x49/0xbe BUG: leak checking failed

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2a20592baff59c5351c5200ec667e1a2aa22af85 < 76a9886e1b61ce5592df5ae78a19ed30399ae18976a9886e1b61ce5592df5ae78a19ed30399ae189
linuxlinux>= 5.10.37 < 5.10.1735.10.173
linuxlinux>= 5.11.21 < 5.125.12
linuxlinux>= 5.12.4 < 5.135.13
linuxlinux>= 5.4.119 < 5.4.2355.4.235
linuxlinux>= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < 999439fd5da5a76253e2f2c37b94204f47d75491999439fd5da5a76253e2f2c37b94204f47d75491
linuxlinux>= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < ccf6a7fb1aedb1472e1241ee55e4d26b68f8d066ccf6a7fb1aedb1472e1241ee55e4d26b68f8d066
linuxlinux>= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < fb436dd6914325075f07d19851ab277b7a693ae7fb436dd6914325075f07d19851ab277b7a693ae7
linuxlinux>= 5d3c4c79384af06e3c8e25b7770b6247496b4417 < b1cb1fac22abf102ffeb29dd3eeca208a3869d54b1cb1fac22abf102ffeb29dd3eeca208a3869d54
linuxlinux>= 7d1bc32d6477ff96a32695ea4be8144e4513ab2d < 10c2a20d73e99463e69b7e92706791656adc16d710c2a20d73e99463e69b7e92706791656adc16d7
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 5.4.2355.4.235
linuxlinux_kernel>= 5.11.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.13.0 < 6.1.166.1.16
linuxlinux_kernel>= 5.16.0 < 6.2.36.2.3
linuxlinux_kernel>= 5.5.0 < 5.10.1735.10.173
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.