[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025122426-CVE-2023-54055-3b5f@gregkh>
Date: Wed, 24 Dec 2025 13:26:48 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...nel.org>
Subject: CVE-2023-54055: RDMA/irdma: Fix memory leak of PBLE objects
From: Greg Kroah-Hartman <gregkh@...nel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
RDMA/irdma: Fix memory leak of PBLE objects
On rmmod of irdma, the PBLE object memory is not being freed. PBLE object
memory are not statically pre-allocated at function initialization time
unlike other HMC objects. PBLEs objects and the Segment Descriptors (SD)
for it can be dynamically allocated during scale up and SD's remain
allocated till function deinitialization.
Fix this leak by adding IRDMA_HMC_IW_PBLE to the iw_hmc_obj_types[] table
and skip pbles in irdma_create_hmc_obj but not in irdma_del_hmc_objects().
The Linux kernel CVE team has assigned CVE-2023-54055 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.14 with commit 44d9e52977a1b90b0db1c7f8b197c218e9226520 and fixed in 5.15.108 with commit 810250c9c6616fe131099c0e51c61f2110ed07bf
Issue introduced in 5.14 with commit 44d9e52977a1b90b0db1c7f8b197c218e9226520 and fixed in 6.1.25 with commit ee02fa4a71bdb95a444124e5c11eaa22f1f44738
Issue introduced in 5.14 with commit 44d9e52977a1b90b0db1c7f8b197c218e9226520 and fixed in 6.2.12 with commit adf58bd4018fbcd990c62e840afd2f178eefad60
Issue introduced in 5.14 with commit 44d9e52977a1b90b0db1c7f8b197c218e9226520 and fixed in 6.3 with commit b69a6979dbaa2453675fe9c71bdc2497fedb11f9
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2023-54055
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/infiniband/hw/irdma/hw.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/810250c9c6616fe131099c0e51c61f2110ed07bf
https://git.kernel.org/stable/c/ee02fa4a71bdb95a444124e5c11eaa22f1f44738
https://git.kernel.org/stable/c/adf58bd4018fbcd990c62e840afd2f178eefad60
https://git.kernel.org/stable/c/b69a6979dbaa2453675fe9c71bdc2497fedb11f9
Powered by blists - more mailing lists