[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025123059-CVE-2023-54266-a48b@gregkh>
Date: Tue, 30 Dec 2025 13:20:32 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...nel.org>
Subject: CVE-2023-54266: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
From: Greg Kroah-Hartman <gregkh@...nel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer()
'read' is freed when it is known to be NULL, but not when a read error
occurs.
Revert the logic to avoid a small leak, should a m920x_read() call fail.
The Linux kernel CVE team has assigned CVE-2023-54266 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.14.263 with commit 82ce3084892c0c0e006ec61f6144f2cc4e5ece88 and fixed in 4.14.326 with commit 809623fedc31f4e74039d93bb75a8993635d7534
Issue introduced in 4.19.226 with commit 7dca4428d7eb33c89979e620228fe557593fde66 and fixed in 4.19.295 with commit c0178e938f110cdf6937f26975c0c951dbb1d9db
Issue introduced in 5.4.174 with commit fe791612afabaeee9b911bd7b955985bcf5ff314 and fixed in 5.4.257 with commit 75d6ef197c488cd852493b4a419274e3489da79d
Issue introduced in 5.10.94 with commit 830e5d1b4344c2575020ee4bdf63fb48e2b56ce3 and fixed in 5.10.195 with commit d13a84874a2e0236c9325b3adc8e126d0888ad6b
Issue introduced in 5.15.17 with commit 0c044e39d52abfbb4cb43dbc5a09c1dc1ed24648 and fixed in 5.15.132 with commit 7ca7cd02114ac8caa6b0a64734b9af6be1559353
Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.1.53 with commit 2b6e20ef0585a467c24c7e4fde28518e5b33225a
Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.4.16 with commit 4feed3dfca722c6d74865a37cab853c58e6aa190
Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.5.3 with commit 2cc9f11aeae2887a4db25c27323fc445f4b49e86
Issue introduced in 5.17 with commit a2ab06d7c4d6bfd0b545a768247a70463e977e27 and fixed in 6.6 with commit ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8
Issue introduced in 4.4.300 with commit 08cb4f0da9926277101d18d817048e1328ac2563
Issue introduced in 4.9.298 with commit 273cac7a89712ba6b898214af150b71dc33abe0c
Issue introduced in 5.16.3 with commit b7e221dc8f23727e00a7fb6709b3318547a7c4d8
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2023-54266
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/media/usb/dvb-usb/m920x.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/809623fedc31f4e74039d93bb75a8993635d7534
https://git.kernel.org/stable/c/c0178e938f110cdf6937f26975c0c951dbb1d9db
https://git.kernel.org/stable/c/75d6ef197c488cd852493b4a419274e3489da79d
https://git.kernel.org/stable/c/d13a84874a2e0236c9325b3adc8e126d0888ad6b
https://git.kernel.org/stable/c/7ca7cd02114ac8caa6b0a64734b9af6be1559353
https://git.kernel.org/stable/c/2b6e20ef0585a467c24c7e4fde28518e5b33225a
https://git.kernel.org/stable/c/4feed3dfca722c6d74865a37cab853c58e6aa190
https://git.kernel.org/stable/c/2cc9f11aeae2887a4db25c27323fc445f4b49e86
https://git.kernel.org/stable/c/ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8
Powered by blists - more mailing lists