CVE-2023-54238 — Missing Release of Resource after Effective Lifetime in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
mlx5: fix skb leak while fifo resync and push
During ptp resync operation SKBs were poped from the fifo but were never
freed neither by napi_consume nor by dev_kfree_skb_any. Add call to
napi_consume_skb to properly free SKBs.
Another leak was happening because mlx5e_skb_fifo_has_room() had an error
in the check. Comparing free running counters works well unless C promotes
the types to something wider than the counter. In thi…
Affected Packages4 packages
▶CVEListV5linux/linux58a518948f60153e8f6cb8361d2712aa3a1af94a — 234cffda95e1049f58e8ec136ef105c633f0ed19+3
🔴Vulnerability Details
3OSV▶
CVE-2023-54238: In the Linux kernel, the following vulnerability has been resolved: mlx5: fix skb leak while fifo resync and push During ptp resync operation SKBs wer↗2025-12-30
GHSA▶
GHSA-48xp-xhc9-g2gm: In the Linux kernel, the following vulnerability has been resolved:
mlx5: fix skb leak while fifo resync and push
During ptp resync operation SKBs w↗2025-12-30