Security Advisory

CVE-2023-54015

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-24 10:55:47
Last updated 2026-05-11 19:53:38
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Devcom, fix error flow in mlx5_devcom_register_device In case devcom allocation is failed, mlx5 is always freeing the priv. However, this priv might have been allocated by a different thread, and freeing it might lead to use-after-free bugs. Fix it by freeing the priv only in case it was allocated by the running thread.