CVE-2023-54169Missing Release of Memory after Effective Lifetime in Linux

Severity
6.2MEDIUM
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix memory leak in mlx5e_ptp_open When kvzalloc_node or kvzalloc failed in mlx5e_ptp_open, the memory pointed by "c" or "cparams" is not freed, which can lead to a memory leak. Fix by freeing the array in the error path.

Affected Packages4 packages

Linuxlinux/linux_kernel5.11.05.15.121+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linux145e5637d941daec2e8d1ff21676cbf1aa62cf4d4892e1e548b5bd6524c1c89df06e4849df26fc20+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-w746-97c4-584x: In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix memory leak in mlx5e_ptp_open When kvzalloc_node or kvzalloc fail2025-12-30
OSV
CVE-2023-54169: In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix memory leak in mlx5e_ptp_open When kvzalloc_node or kvzalloc failed2025-12-30
OSV
net/mlx5e: fix memory leak in mlx5e_ptp_open2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: net/mlx5e: fix memory leak in mlx5e_ptp_open2025-12-30
Debian
CVE-2023-54169: linux - In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: ...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54169 Impact, Exploitability, and Mitigation Steps | Wiz