CVE-2023-54081
published 2025-12-24CVE-2023-54081: In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote domain…
PriorityP423medium6.2
EPSS
0.18%
7.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. The default is still
10, but it can be overridden via a module parameter.
This is Cc: stable because (when combined with appropriate userspace
changes) it fixes a severe performance and stability problem for Qubes
OS users.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 569ca5b3f94cd0b3295ec5943aa457cf4a4f6a3a < cd1a8952ff529adc210e62306849fd6f256608c0 | cd1a8952ff529adc210e62306849fd6f256608c0 |
| linux | linux | >= 569ca5b3f94cd0b3295ec5943aa457cf4a4f6a3a < c76d96c555895ac602c1587b001e5cf656abc371 | c76d96c555895ac602c1587b001e5cf656abc371 |
| linux | linux | >= 569ca5b3f94cd0b3295ec5943aa457cf4a4f6a3a < c04e9894846c663f3278a414f34416e6e45bbe68 | c04e9894846c663f3278a414f34416e6e45bbe68 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 3.5.0 < 6.1.43 | 6.1.43 |
| linux | linux_kernel | >= 6.2.0 < 6.4.8 | 6.4.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x4pm-f62g-mp4x: In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remo
ghsa_unreviewed·2025-12-24
CVE-2023-54081 GHSA-x4pm-f62g-mp4x: In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remo
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. The default is still
10, but it can be overridden via a module parameter.
This is Cc: stable because
OSV
CVE-2023-54081: In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote
osv·2025-12-24
CVE-2023-54081 CVE-2023-54081: In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote
In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote domain, Linux must put it on a deferred list. Normally, this list is very short, because the PV network and block protocols expect the backend to unmap the grant first. However, Qubes OS's GUI protocol is subject to the constraints of the X Window System, and as such winds up with the frontend unmapping the window first. As a result, the list can grow very large, resulting in a massive memory leak and eventual VM freeze. To partially solve this problem, make the number of entries that the VM will attempt to free at each iteration tunable. The default is still 10, but it can be overridden via a module parameter. This is Cc: stable because (wh
OSV
xen: speed up grant-table reclaim
osv·2025-12-24
CVE-2023-54081 xen: speed up grant-table reclaim
xen: speed up grant-table reclaim
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. The default is still
10, but it can be overridden via a module par
Red Hat
kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
vendor_redhat·2025-12-24·CVSS 6.2
CVE-2023-54081 [MEDIUM] CWE-400 kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. The default is still
Debian
CVE-2023-54081: linux - In the Linux kernel, the following vulnerability has been resolved: xen: speed ...
vendor_debian·2023
CVE-2023-54081 CVE-2023-54081: linux - In the Linux kernel, the following vulnerability has been resolved: xen: speed ...
In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote domain, Linux must put it on a deferred list. Normally, this list is very short, because the PV network and block protocols expect the backend to unmap the grant first. However, Qubes OS's GUI protocol is subject to the constraints of the X Window System, and as such winds up with the frontend unmapping the window first. As a result, the list can grow very large, resulting in a massive memory leak and eventual VM freeze. To partially solve this problem, make the number of entries that the VM will attempt to free at each iteration tunable. The default is still 10, but it can be overridden via a module parameter. This is Cc: stable because (wh
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54081 kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
bugzilla·2025-12-24
CVE-2023-54081 [MEDIUM] CVE-2023-54081 kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
CVE-2023-54081 kernel: Linux kernel: Denial of Service in Xen grant table reclaim via memory leak
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. Th
Wiz
CVE-2023-54081 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54081 CVE-2023-54081 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54081 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
xen: speed up grant-table reclaim
When a grant entry is still in use by the remote domain, Linux must put
it on a deferred list. Normally, this list is very short, because
the PV network and block protocols expect the backend to unmap the grant
first. However, Qubes OS's GUI protocol is subject to the constraints
of the X Window System, and as such winds up with the frontend unmapping
the window first. As a result, the list can grow very large, resulting
in a massive memory leak and eventual VM freeze.
To partially solve this problem, make the number of entries that the VM
will attempt to free at each iteration tunable. The default is still
10, but
2025-12-24
Published