CVE-2023-54015
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/12/2025
Last modified:
29/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device<br />
<br />
In case devcom allocation is failed, mlx5 is always freeing the priv.<br />
However, this priv might have been allocated by a different thread,<br />
and freeing it might lead to use-after-free bugs.<br />
Fix it by freeing the priv only in case it was allocated by the<br />
running thread.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1e755065368000205e6683fa924b2654e99f573b
- https://git.kernel.org/stable/c/3dfc1004d9afbf689087ae1eafd88f55481984c7
- https://git.kernel.org/stable/c/a3a516caef2c5be2f4d171890a8b3415bfab4e5e
- https://git.kernel.org/stable/c/af87194352cad882d787d06fb7efa714acd95427
- https://git.kernel.org/stable/c/d4d10a6df1529b3f446cdada5c25e065f4712756
- https://git.kernel.org/stable/c/eaa365c10459052cbe3e44caa4ad760cb93bd435



