CVE-2023-54015

medium

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device In case devcom allocation is failed, mlx5 is always freeing the priv. However, this priv might have been allocated by a different thread, and freeing it might lead to use-after-free bugs. Fix it by freeing the priv only in case it was allocated by the running thread.

References

https://git.kernel.org/stable/c/eaa365c10459052cbe3e44caa4ad760cb93bd435

https://git.kernel.org/stable/c/d4d10a6df1529b3f446cdada5c25e065f4712756

https://git.kernel.org/stable/c/af87194352cad882d787d06fb7efa714acd95427

https://git.kernel.org/stable/c/a3a516caef2c5be2f4d171890a8b3415bfab4e5e

https://git.kernel.org/stable/c/3dfc1004d9afbf689087ae1eafd88f55481984c7

https://git.kernel.org/stable/c/1e755065368000205e6683fa924b2654e99f573b

Details

Source: Mitre, NVD

Published: 2025-12-24

Updated: 2025-12-24

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024