CVE-2023-54015 is a use-after-free vulnerability in the Linux kernel's mlx5 network driver. It arises from improper handling of device private data (priv) during devcom allocation failures, where the driver might free memory allocated by a different thread. While no specific affected products are listed, this flaw impacts Linux systems utilizing the mlx5 driver. The vulnerability's severity is currently unrated by CVSS, but its potential for use-after-free bugs suggests a risk of system instability or privilege escalation. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.0CNA affecteddefault affected | |
| Linux | Linux | >= fadd59fc50d010145f251db583c7ccef37393d19, < 1e755065368000205e6683fa924b2654e99f573b, >= fadd59fc50d010145f251db583c7ccef37393d19, < 3dfc1004d9afbf689087ae1eafd88f55481984c7, >= fadd59fc50d010145f251db583c7ccef37393d19, < a3a516caef2c5be2f4d171890a8b3415bfab4e5e, >= fadd59fc50d010145f251db583c7ccef37393d19, < af87194352cad882d787d06fb7efa714acd95427, >= fadd59fc50d010145f251db583c7ccef37393d19, < d4d10a6df1529b3f446cdada5c25e065f4712756, >= fadd59fc50d010145f251db583c7ccef37393d19, < eaa365c10459052cbe3e44caa4ad760cb93bd435CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.