CVE-2023-54215Missing Release of Resource after Effective Lifetime in Linux

Severity
3.3LOW
No vector
EPSS
0.0%
top 92.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask allocated by create_affinity_masks() before returning from the function.

Affected Packages4 packages

Linuxlinux/linux_kernel6.4.06.4.12
Debianlinux/linux_kernel< 6.4.13-1+1
CVEListV5linux/linux3dad56823b5332ffdbe1867b2d7b50fbacea124afa450621efab58121fe8e57f7a7b80fee6e0bae1+2
debiandebian/linux< linux 6.4.13-1 (forky)

🔴Vulnerability Details

3
GHSA
GHSA-g4v8-cg96-4xjg: In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask2025-12-30
OSV
CVE-2023-54215: In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask al2025-12-30
OSV
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()2025-12-30
Debian
CVE-2023-54215: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54215 Impact, Exploitability, and Mitigation Steps | Wiz