CVE-2023-54106Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to by the priv->rx_res pointer is not freed in the error path of mlx5e_init_rep_rx, which can lead to a memory leak. Fix by freeing the memory in the error path, thereby making the error path identical to mlx5e_cleanup_rep_rx().

Affected Packages4 packages

Linuxlinux/linux_kernel6.0.06.1.45+1
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linuxaf8bbf7300686961f74e72e2dc10a76672603cb30582a3caaa3e2f7b80bcb113ad3c910eac15a63e+3
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2023-54106: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to by2025-12-24
GHSA
GHSA-2c4h-2ghg-m6fj: In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to b2025-12-24
OSV
net/mlx5: fix potential memory leak in mlx5e_init_rep_rx2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service via memory leak in mlx5e_init_rep_rx2025-12-24
Debian
CVE-2023-54106: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5: f...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54106 Impact, Exploitability, and Mitigation Steps | Wiz