CVE-2023-53371

MEDIUM

Linux Kernel 5.13-6.1.39, 6.4.0-6.4.4, 6.5+ - Use-After-Free in mlx5e_fs_tt_redirect_any_create

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create The memory pointed to by the fs->any pointer is not freed in the error path of mlx5e_fs_tt_redirect_any_create, which can lead to a memory leak. Fix by freeing the memory in the error path, thereby making the error path identical to mlx5e_fs_tt_redirect_any_destroy().

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (10)
Linux/Linux < 5.13
Linux/Linux 0f575c20bf0686caf3d82d6c626c2e1e4a4c36e6 - 3250affdc658557a41df9c5fb567723e421f8bf2
Linux/Linux 0f575c20bf0686caf3d82d6c626c2e1e4a4c36e6 - 75df2fe6d160e16be880aacacd521b135d7177c9
Linux/Linux 0f575c20bf0686caf3d82d6c626c2e1e4a4c36e6 - 8a75a6f169c3df3a94802314aa61282772ac75b8
Linux/Linux 5.13
Linux/Linux 6.1.40 - 6.1.*
Linux/Linux 6.4.5 - 6.4.*
Linux/Linux 6.5
linux/linux_kernel 6.5 rc1
linux/linux_kernel 5.13 - 6.1.40
Published Sep 18, 2025
Tracked Since Feb 18, 2026