lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025123059-CVE-2023-54266-a48b@gregkh>
Date: Tue, 30 Dec 2025 13:20:32 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...nel.org>
Subject: CVE-2023-54266: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()

From: Greg Kroah-Hartman <gregkh@...nel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()

'read' is freed when it is known to be NULL, but not when a read error
occurs.

Revert the logic to avoid a small leak, should a m920x_read() call fail.

The Linux kernel CVE team has assigned CVE-2023-54266 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.14.263 with commit 82ce3084892c0c0e006ec61f6144f2cc4e5ece88 and fixed in 4.14.326 with commit 809623fedc31f4e74039d93bb75a8993635d7534
	Issue introduced in 4.19.226 with commit 7dca4428d7eb33c89979e620228fe557593fde66 and fixed in 4.19.295 with commit c0178e938f110cdf6937f26975c0c951dbb1d9db
	Issue introduced in 5.4.174 with commit fe791612afabaeee9b911bd7b955985bcf5ff314 and fixed in 5.4.257 with commit 75d6ef197c488cd852493b4a419274e3489da79d
	Issue introduced in 5.10.94 with commit 830e5d1b4344c2575020ee4bdf63fb48e2b56ce3 and fixed in 5.10.195 with commit d13a84874a2e0236c9325b3adc8e126d0888ad6b
	Issue introduced in 5.15.17 with commit 0c044e39d52abfbb4cb43dbc5a09c1dc1ed24648 and fixed in 5.15.132 with commit 7ca7cd02114ac8caa6b0a64734b9af6be1559353
	Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.1.53 with commit 2b6e20ef0585a467c24c7e4fde28518e5b33225a
	Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.4.16 with commit 4feed3dfca722c6d74865a37cab853c58e6aa190
	Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.5.3 with commit 2cc9f11aeae2887a4db25c27323fc445f4b49e86
	Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.6 with commit ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8
	Issue introduced in 4.4.300 with commit 08cb4f0da9926277101d18d817048e1328ac2563
	Issue introduced in 4.9.298 with commit 273cac7a89712ba6b898214af150b71dc33abe0c
	Issue introduced in 5.16.3 with commit b7e221dc8f23727e00a7fb6709b3318547a7c4d8

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2023-54266
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/media/usb/dvb-usb/m920x.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/809623fedc31f4e74039d93bb75a8993635d7534
	https://git.kernel.org/stable/c/c0178e938f110cdf6937f26975c0c951dbb1d9db
	https://git.kernel.org/stable/c/75d6ef197c488cd852493b4a419274e3489da79d
	https://git.kernel.org/stable/c/d13a84874a2e0236c9325b3adc8e126d0888ad6b
	https://git.kernel.org/stable/c/7ca7cd02114ac8caa6b0a64734b9af6be1559353
	https://git.kernel.org/stable/c/2b6e20ef0585a467c24c7e4fde28518e5b33225a
	https://git.kernel.org/stable/c/4feed3dfca722c6d74865a37cab853c58e6aa190
	https://git.kernel.org/stable/c/2cc9f11aeae2887a4db25c27323fc445f4b49e86
	https://git.kernel.org/stable/c/ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ