CVE-2023-54266Missing Release of Memory after Effective Lifetime in Linux

7 documents6 sources
Severity
N/A
No vector
EPSS
0.0%
top 84.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.

Affected Packages4 packages

Linuxlinux/linux_kernel4.15.04.19.295+7
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linux82ce3084892c0c0e006ec61f6144f2cc4e5ece88809623fedc31f4e74039d93bb75a8993635d7534+12
debiandebian/linux< linux 6.1.55-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-76fv-99ww-8hmg: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is2025-12-30
OSV
CVE-2023-54266: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is f2025-12-30
OSV
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()2025-12-30
Debian
CVE-2023-54266: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54266 Impact, Exploitability, and Mitigation Steps | Wiz