CVE-2023-54123
published 2025-12-24CVE-2023-54123: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak for 'conf->bio_split' In the error path of raid10_run(), 'conf' need…
PriorityP418low5.5
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < 133008af833b4f2e021d2c294c29c70364a3f0ba | 133008af833b4f2e021d2c294c29c70364a3f0ba |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < b6460f68c1cc95a80d089af402be501619f228e4 | b6460f68c1cc95a80d089af402be501619f228e4 |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < 6361b0592b46c465ac926c1f3105d66c30d9658b | 6361b0592b46c465ac926c1f3105d66c30d9658b |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < 7f673fa34c0e3f95ee951a1bbf61791164871d2e | 7f673fa34c0e3f95ee951a1bbf61791164871d2e |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < b21019a220d9cac08819bb6c63000de9ee61eb9e | b21019a220d9cac08819bb6c63000de9ee61eb9e |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < 5cba3e26c073b535e4e3b825ea481fb29c53943b | 5cba3e26c073b535e4e3b825ea481fb29c53943b |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < e2fec8d95353a48634b085011626ba3ec8ab8b1c | e2fec8d95353a48634b085011626ba3ec8ab8b1c |
| linux | linux | >= fc9977dd069e4f82fcacb262652117c488647319 < c9ac2acde53f5385de185bccf6aaa91cf9ac1541 | c9ac2acde53f5385de185bccf6aaa91cf9ac1541 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.12.0 < 4.19.283 | 4.19.283 |
| linux | linux_kernel | >= 4.20.0 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 5.11.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 5.5.0 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54123: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak for 'conf->bio_split' In the error path of raid10_run(), 'c
osv·2025-12-24
CVE-2023-54123 CVE-2023-54123: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak for 'conf->bio_split' In the error path of raid10_run(), 'c
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak for 'conf->bio_split' In the error path of raid10_run(), 'conf' need be freed, however, 'conf->bio_split' is missed and memory will be leaked. Since there are 3 places to free 'conf', factor out a helper to fix the problem.
GHSA
GHSA-fggm-fgvr-h4xg: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(),
ghsa_unreviewed·2025-12-24
CVE-2023-54123 GHSA-fggm-fgvr-h4xg: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(),
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
OSV
md/raid10: fix memleak for 'conf->bio_split'
osv·2025-12-24
CVE-2023-54123 md/raid10: fix memleak for 'conf->bio_split'
md/raid10: fix memleak for 'conf->bio_split'
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
Red Hat
kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54123 [LOW] CWE-772 kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
A flaw was found in the Linux kernel. This vulnerability, a memory leak, occurs within the RAID10 functionality when handling certain error conditions. A local attacker with low privileges could exploit this by triggering the specific error path, potentially leading to a denial of service (DoS) due to system resource exhaustion.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: ker
Debian
CVE-2023-54123: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
vendor_debian·2023
CVE-2023-54123 CVE-2023-54123: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak for 'conf->bio_split' In the error path of raid10_run(), 'conf' need be freed, however, 'conf->bio_split' is missed and memory will be leaked. Since there are 3 places to free 'conf', factor out a helper to fix the problem.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54123 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54123 CVE-2023-54123 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54123 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-64k-modules-internal
kernel-cross-headers
Sources
NVD
Debian 11, 12, 13
Bugzilla
CVE-2023-54123 kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
bugzilla·2025-12-24
CVE-2023-54123 [LOW] CVE-2023-54123 kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
CVE-2023-54123 kernel: Kernel: Denial of Service due to memory leak in RAID10 functionality
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak for 'conf->bio_split'
In the error path of raid10_run(), 'conf' need be freed, however,
'conf->bio_split' is missed and memory will be leaked.
Since there are 3 places to free 'conf', factor out a helper to fix the
problem.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122417-CVE-2023-54123-4e1b@gregkh/T
https://git.kernel.org/stable/c/133008af833b4f2e021d2c294c29c70364a3f0bahttps://git.kernel.org/stable/c/5cba3e26c073b535e4e3b825ea481fb29c53943bhttps://git.kernel.org/stable/c/6361b0592b46c465ac926c1f3105d66c30d9658bhttps://git.kernel.org/stable/c/7f673fa34c0e3f95ee951a1bbf61791164871d2ehttps://git.kernel.org/stable/c/b21019a220d9cac08819bb6c63000de9ee61eb9ehttps://git.kernel.org/stable/c/b6460f68c1cc95a80d089af402be501619f228e4https://git.kernel.org/stable/c/c9ac2acde53f5385de185bccf6aaa91cf9ac1541https://git.kernel.org/stable/c/e2fec8d95353a48634b085011626ba3ec8ab8b1c
2025-12-24
Published