cbcvebase.
CVE-2023-54171
published 2025-12-30

CVE-2023-54171: In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory leak of iter->temp when reading trace_pipe kmemleak reports…

PriorityP419low3.3
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix memory leak of iter->temp when reading trace_pipe kmemleak reports: unreferenced object 0xffff88814d14e200 (size 256): comm "cat", pid 336, jiffies 4294871818 (age 779.490s) hex dump (first 32 bytes): 04 00 01 03 00 00 00 00 08 00 00 00 00 00 00 00 ................ 0c d8 c8 9b ff ff ff ff 04 5a ca 9b ff ff ff ff .........Z...... backtrace: [] __kmalloc+0x4f/0x140 [] trace_find_next_entry+0xbb/0x1d0 [] trace_print_lat_context+0xaf/0x4e0 [] print_trace_line+0x3e0/0x950 [] tracing_read_pipe+0x2d9/0x5a0 [] vfs_read+0x143/0x520 [] ksys_read+0xbd/0x160 [] do_syscall_64+0x3f/0x90 [] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 when reading file 'trace_pipe', 'iter->temp' is allocated or relocated in trace_find_next_entry() but not freed before 'trace_pipe' is closed. To fix it, free 'iter->temp' in tracing_release_pipe().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= ff895103a84abc85a5f43ecabc7f67cf36e1348f < 1a1e793e021d75cd0accd8f329ec9456e5cd105e1a1e793e021d75cd0accd8f329ec9456e5cd105e
linuxlinux>= ff895103a84abc85a5f43ecabc7f67cf36e1348f < 954792db9f61b6c0b8a94b8831fed5f146014029954792db9f61b6c0b8a94b8831fed5f146014029
linuxlinux>= ff895103a84abc85a5f43ecabc7f67cf36e1348f < be970e22c53d5572b2795b79da9716ada937023bbe970e22c53d5572b2795b79da9716ada937023b
linuxlinux>= ff895103a84abc85a5f43ecabc7f67cf36e1348f < 3f42d57a76e7e96585f08855554e002218cbca0c3f42d57a76e7e96585f08855554e002218cbca0c
linuxlinux>= ff895103a84abc85a5f43ecabc7f67cf36e1348f < d5a821896360cc8b93a15bd888fabc858c038dc0d5a821896360cc8b93a15bd888fabc858c038dc0
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.11.0 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16.0 < 6.1.406.1.40
linuxlinux_kernel>= 5.7.0 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2.0 < 6.4.56.4.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.