CVE-2023-54015
Published: December 26, 2025Last modified: December 26, 2025
Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device In case devcom allocation is failed, mlx5 is always freeing the priv. However, this priv might have been allocated by a different thread, and freeing it might lead to use-after-free bugs. Fix it by freeing the priv only in case it was allocated by the running thread.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Not affected (6.1.33-r0) |
| 25 LTS | linux-lts | Not affected (6.6.89-r0) | |
| Stream | linux-lts | Fixed (6.6.58-r0) |
References
- https://git.kernel.org/stable/c/1e755065368000205e6683fa924b2654e99f573b
- https://git.kernel.org/stable/c/3dfc1004d9afbf689087ae1eafd88f55481984c7
- https://git.kernel.org/stable/c/a3a516caef2c5be2f4d171890a8b3415bfab4e5e
- https://git.kernel.org/stable/c/af87194352cad882d787d06fb7efa714acd95427
- https://git.kernel.org/stable/c/d4d10a6df1529b3f446cdada5c25e065f4712756
- https://git.kernel.org/stable/c/eaa365c10459052cbe3e44caa4ad760cb93bd435