CVE-2023-54266
published 2025-12-30CVE-2023-54266: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when…
PriorityP418
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0c044e39d52abfbb4cb43dbc5a09c1dc1ed24648 < 7ca7cd02114ac8caa6b0a64734b9af6be1559353 | 7ca7cd02114ac8caa6b0a64734b9af6be1559353 |
| linux | linux | >= 4.14.263 < 4.14.326 | 4.14.326 |
| linux | linux | >= 4.19.226 < 4.19.295 | 4.19.295 |
| linux | linux | >= 4.4.300 < 4.5 | 4.5 |
| linux | linux | >= 4.9.298 < 4.10 | 4.10 |
| linux | linux | >= 5.10.94 < 5.10.195 | 5.10.195 |
| linux | linux | >= 5.15.17 < 5.15.132 | 5.15.132 |
| linux | linux | >= 5.16.3 < 5.17 | 5.17 |
| linux | linux | >= 5.4.174 < 5.4.257 | 5.4.257 |
| linux | linux | >= 7dca4428d7eb33c89979e620228fe557593fde66 < c0178e938f110cdf6937f26975c0c951dbb1d9db | c0178e938f110cdf6937f26975c0c951dbb1d9db |
| linux | linux | >= 82ce3084892c0c0e006ec61f6144f2cc4e5ece88 < 809623fedc31f4e74039d93bb75a8993635d7534 | 809623fedc31f4e74039d93bb75a8993635d7534 |
| linux | linux | >= 830e5d1b4344c2575020ee4bdf63fb48e2b56ce3 < d13a84874a2e0236c9325b3adc8e126d0888ad6b | d13a84874a2e0236c9325b3adc8e126d0888ad6b |
| linux | linux | >= a2ab06d7c4d6bfd0b545a768247a70463e977e27 < 2b6e20ef0585a467c24c7e4fde28518e5b33225a | 2b6e20ef0585a467c24c7e4fde28518e5b33225a |
| linux | linux | >= a2ab06d7c4d6bfd0b545a768247a70463e977e27 < 4feed3dfca722c6d74865a37cab853c58e6aa190 | 4feed3dfca722c6d74865a37cab853c58e6aa190 |
| linux | linux | >= a2ab06d7c4d6bfd0b545a768247a70463e977e27 < 2cc9f11aeae2887a4db25c27323fc445f4b49e86 | 2cc9f11aeae2887a4db25c27323fc445f4b49e86 |
| linux | linux | >= a2ab06d7c4d6bfd0b545a768247a70463e977e27 < ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8 | ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8 |
| linux | linux | >= fe791612afabaeee9b911bd7b955985bcf5ff314 < 75d6ef197c488cd852493b4a419274e3489da79d | 75d6ef197c488cd852493b4a419274e3489da79d |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-76fv-99ww-8hmg: In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is
ghsa_unreviewed·2025-12-30
CVE-2023-54266 GHSA-76fv-99ww-8hmg: In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
OSV
CVE-2023-54266: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is f
osv·2025-12-30
CVE-2023-54266 CVE-2023-54266: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is f
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.
OSV
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
osv·2025-12-30
CVE-2023-54266 media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
Red Hat
kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
vendor_redhat·2025-12-30
CVE-2023-54266 kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affe
Debian
CVE-2023-54266: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...
vendor_debian·2023
CVE-2023-54266 CVE-2023-54266: linux - In the Linux kernel, the following vulnerability has been resolved: media: dvb-...
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54266 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54266 CVE-2023-54266 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54266 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtb-mediatek
linux-oracle-5.15
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo
Bugzilla
CVE-2023-54266 kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
bugzilla·2025-12-30
CVE-2023-54266 CVE-2023-54266 kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
CVE-2023-54266 kernel: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123059-CVE-2023-54266-a48b@gregkh/T
https://git.kernel.org/stable/c/2b6e20ef0585a467c24c7e4fde28518e5b33225ahttps://git.kernel.org/stable/c/2cc9f11aeae2887a4db25c27323fc445f4b49e86https://git.kernel.org/stable/c/4feed3dfca722c6d74865a37cab853c58e6aa190https://git.kernel.org/stable/c/75d6ef197c488cd852493b4a419274e3489da79dhttps://git.kernel.org/stable/c/7ca7cd02114ac8caa6b0a64734b9af6be1559353https://git.kernel.org/stable/c/809623fedc31f4e74039d93bb75a8993635d7534https://git.kernel.org/stable/c/c0178e938f110cdf6937f26975c0c951dbb1d9dbhttps://git.kernel.org/stable/c/d13a84874a2e0236c9325b3adc8e126d0888ad6bhttps://git.kernel.org/stable/c/ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8
2025-12-30
Published