cbcvebase.
CVE-2023-54041
published 2025-12-24

CVE-2023-54041: In the Linux kernel, the following vulnerability has been resolved: io_uring: fix memory leak when removing provided buffers When removing provided buffers…

PriorityP417low5.5
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix memory leak when removing provided buffers When removing provided buffers, io_buffer structs are not being disposed of, leading to a memory leak. They can't be freed individually, because they are allocated in page-sized groups. They need to be added to some free list instead, such as io_buffers_cache. All callers already hold the lock protecting it, apart from when destroying buffers, so had to extend the lock there.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= cc3cec8367cba76a8ae4c271eba8450f3efc1ba3 < ac48787f58d1068f4e06d627c1135784d64b4c72ac48787f58d1068f4e06d627c1135784d64b4c72
linuxlinux>= cc3cec8367cba76a8ae4c271eba8450f3efc1ba3 < c117c15927772d1624c29c092b6bd3f47c7faa48c117c15927772d1624c29c092b6bd3f47c7faa48
linuxlinux>= cc3cec8367cba76a8ae4c271eba8450f3efc1ba3 < b4a72c0589fdea6259720375426179888969d6a2b4a72c0589fdea6259720375426179888969d6a2
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.18.0 < 6.1.246.1.24
linuxlinux_kernel>= 6.2.0 < 6.2.116.2.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.