CVE-2023-54294
published 2025-12-30CVE-2023-54294: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak of md thread In raid10_run(), if setup_conf() succeed and…
PriorityP417low3.3
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < abf4d67060c8f63caff096e5fca1564bfef1e5d4 | abf4d67060c8f63caff096e5fca1564bfef1e5d4 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < 3725b35fc0e5e4eea0434ef625f3d92f3059d080 | 3725b35fc0e5e4eea0434ef625f3d92f3059d080 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < 2a65555f7e0f4a05b663879908a991e6d9f81e51 | 2a65555f7e0f4a05b663879908a991e6d9f81e51 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < d6cfcf98b824591cffa4c1e9889fb4fa619359fe | d6cfcf98b824591cffa4c1e9889fb4fa619359fe |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < 36ba0c7b86acd9c2ea80a273204d52c21c955471 | 36ba0c7b86acd9c2ea80a273204d52c21c955471 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < 5d763f708b0f918fb87799e33c25113ae6081216 | 5d763f708b0f918fb87799e33c25113ae6081216 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < ec473e82e10d39a02eb59b0b95e546119a3bdb79 | ec473e82e10d39a02eb59b0b95e546119a3bdb79 |
| linux | linux | >= 43a521238aca0e24d50add1db125a61bda2a3527 < f0ddb83da3cbbf8a1f9087a642c448ff52ee9abd | f0ddb83da3cbbf8a1f9087a642c448ff52ee9abd |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.16.0 < 4.19.283 | 4.19.283 |
| linux | linux_kernel | >= 4.20.0 < 5.4.243 | 5.4.243 |
| linux | linux_kernel | >= 5.11.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 5.5.0 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.3.1 raid10_run memory leak (Nessus ID 319480 / WID-SEC-2025-2941)
vuldb·2026-06-07
CVE-2023-54294 [CRITICAL] Linux Kernel up to 6.3.1 raid10_run memory leak (Nessus ID 319480 / WID-SEC-2025-2941)
A vulnerability has been found in Linux Kernel up to 6.3.1 and classified as critical. Affected by this issue is the function raid10_run. This manipulation causes memory leak.
This vulnerability is registered as CVE-2023-54294. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
OSV
md/raid10: fix memleak of md thread
osv·2025-12-30
CVE-2023-54294 md/raid10: fix memleak of md thread
md/raid10: fix memleak of md thread
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
OSV
CVE-2023-54294: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak of md thread In raid10_run(), if setup_conf() succeed and r
osv·2025-12-30
CVE-2023-54294 CVE-2023-54294: In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak of md thread In raid10_run(), if setup_conf() succeed and r
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak of md thread In raid10_run(), if setup_conf() succeed and raid10_run() failed before setting 'mddev->thread', then in the error path 'conf->thread' is not freed. Fix the problem by setting 'mddev->thread' right after setup_conf().
GHSA
GHSA-cpq6-27xg-r565: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and
ghsa_unreviewed·2025-12-30
CVE-2023-54294 GHSA-cpq6-27xg-r565: In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
Red Hat
kernel: md/raid10: fix memleak of md thread
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2023-54294 [LOW] CWE-772 kernel: md/raid10: fix memleak of md thread
kernel: md/raid10: fix memleak of md thread
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
A memory leak was found in the MD RAID10 driver. When raid10_run() fails after setup_conf() succeeds but before mddev->thread is set, the conf->thread is not freed, leaking kernel thread resources.
Statement: This leak occurs only when RAID10 array assembly fails at a specific point. The impact is limited to systems attempting to assemble RAID10 arrays that fail for other reasons during the run phase.
Package: kernel (Red Hat
Debian
CVE-2023-54294: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
vendor_debian·2023
CVE-2023-54294 CVE-2023-54294: linux - In the Linux kernel, the following vulnerability has been resolved: md/raid10: ...
In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix memleak of md thread In raid10_run(), if setup_conf() succeed and raid10_run() failed before setting 'mddev->thread', then in the error path 'conf->thread' is not freed. Fix the problem by setting 'mddev->thread' right after setup_conf().
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54294 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54294 CVE-2023-54294 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54294 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-debug-modules
kernel-rt-modules-core
Sources
NVD
Debian 11,
Bugzilla
CVE-2023-54294 kernel: md/raid10: fix memleak of md thread
bugzilla·2025-12-30
CVE-2023-54294 [LOW] CVE-2023-54294 kernel: md/raid10: fix memleak of md thread
CVE-2023-54294 kernel: md/raid10: fix memleak of md thread
In the Linux kernel, the following vulnerability has been resolved:
md/raid10: fix memleak of md thread
In raid10_run(), if setup_conf() succeed and raid10_run() failed before
setting 'mddev->thread', then in the error path 'conf->thread' is not
freed.
Fix the problem by setting 'mddev->thread' right after setup_conf().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123030-CVE-2023-54294-e7ac@gregkh/T
https://git.kernel.org/stable/c/2a65555f7e0f4a05b663879908a991e6d9f81e51https://git.kernel.org/stable/c/36ba0c7b86acd9c2ea80a273204d52c21c955471https://git.kernel.org/stable/c/3725b35fc0e5e4eea0434ef625f3d92f3059d080https://git.kernel.org/stable/c/5d763f708b0f918fb87799e33c25113ae6081216https://git.kernel.org/stable/c/abf4d67060c8f63caff096e5fca1564bfef1e5d4https://git.kernel.org/stable/c/d6cfcf98b824591cffa4c1e9889fb4fa619359fehttps://git.kernel.org/stable/c/ec473e82e10d39a02eb59b0b95e546119a3bdb79https://git.kernel.org/stable/c/f0ddb83da3cbbf8a1f9087a642c448ff52ee9abd
2025-12-30
Published