CVE-2023-54215
published 2025-12-30CVE-2023-54215: In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask allocated…
PriorityP417low3.3
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.4.13-1 (forky) | linux 6.4.13-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 3dad56823b5332ffdbe1867b2d7b50fbacea124a < fa450621efab58121fe8e57f7a7b80fee6e0bae1 | fa450621efab58121fe8e57f7a7b80fee6e0bae1 |
| linux | linux | >= 3dad56823b5332ffdbe1867b2d7b50fbacea124a < df9557046440b0a62250fee3169a8f6a139f55a6 | df9557046440b0a62250fee3169a8f6a139f55a6 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| linux | linux_kernel | >= 0 < 6.4.13-1 | 6.4.13-1 |
| linux | linux_kernel | >= 6.4.0 < 6.4.12 | 6.4.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g4v8-cg96-4xjg: In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask
ghsa_unreviewed·2025-12-30
CVE-2023-54215 GHSA-g4v8-cg96-4xjg: In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
OSV
CVE-2023-54215: In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask al
osv·2025-12-30
CVE-2023-54215 CVE-2023-54215: In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask al
In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask allocated by create_affinity_masks() before returning from the function.
OSV
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
osv·2025-12-30
CVE-2023-54215 virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
Red Hat
kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2023-54215 [LOW] CWE-772 kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
A memory leak was found in the virtio-vdpa driver. The cpumask allocated by create_affinity_masks() is not freed before the function returns, causing a small memory leak each time virtqueues are set up.
Statement: This leak occurs during virtio-vdpa device initialization, primarily in virtualization environments using vDPA. The leaked memory is small per occurrence but could accumulate with repeated device operations.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red
Debian
CVE-2023-54215: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa...
vendor_debian·2023
CVE-2023-54215 [LOW] CVE-2023-54215: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa...
In the Linux kernel, the following vulnerability has been resolved: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs() Free the cpumask allocated by create_affinity_masks() before returning from the function.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.4.13-1)
sid: resolved (fixed in 6.4.13-1)
trixie: resolved (fixed in 6.4.13-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54215 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54215 CVE-2023-54215 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54215 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-64k-devel-matched
kernel-zfcpdump-modules
Sources
NVD
Debian 13, 14 Has Fix Added at: Dec 31, 2025
Red Hat 9 Severity LOW Has Fix Added at: Dec 31, 2025
Ubuntu 16.04
Bugzilla
CVE-2023-54215 kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
bugzilla·2025-12-30
CVE-2023-54215 [LOW] CVE-2023-54215 kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
CVE-2023-54215 kernel: virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
In the Linux kernel, the following vulnerability has been resolved:
virtio-vdpa: Fix cpumask memory leak in virtio_vdpa_find_vqs()
Free the cpumask allocated by create_affinity_masks() before returning
from the function.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123025-CVE-2023-54215-d1c0@gregkh/T
2025-12-30
Published