CVE-2023-54266

UnknownEPSS 0.19%

Last modified

CVE-2023-54266 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.

Metrics

EPSS Probability
0.19%

9.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 82ce3084892c0c0e006ec61f6144f2cc4e5ece88, < 809623fedc31f4e74039d93bb75a8993635d7534; >= 7dca4428d7eb33c89979e620228fe557593fde66, < c0178e938f110cdf6937f26975c0c951dbb1d9db; >= fe791612afabaeee9b911bd7b955985bcf5ff314, < 75d6ef197c488cd852493b4a419274e3489da79d; >= 830e5d1b4344c2575020ee4bdf63fb48e2b56ce3, < d13a84874a2e0236c9325b3adc8e126d0888ad6b; >= 0c044e39d52abfbb4cb43dbc5a09c1dc1ed24648, < 7ca7cd02114ac8caa6b0a64734b9af6be1559353; >= a2ab06d7c4d6bfd0b545a768247a70463e977e27, < 2b6e20ef0585a467c24c7e4fde28518e5b33225a; >= a2ab06d7c4d6bfd0b545a768247a70463e977e27, < 4feed3dfca722c6d74865a37cab853c58e6aa190; >= a2ab06d7c4d6bfd0b545a768247a70463e977e27, < 2cc9f11aeae2887a4db25c27323fc445f4b49e86; >= a2ab06d7c4d6bfd0b545a768247a70463e977e27, < ea9ef6c2e001c5dc94bee35ebd1c8a98621cf7b8; 08cb4f0da9926277101d18d817048e1328ac2563; 273cac7a89712ba6b898214af150b71dc33abe0c; b7e221dc8f23727e00a7fb6709b3318547a7c4d8; >= 4.14.263, < 4.14.326; >= 4.19.226, < 4.19.295; >= 5.4.174, < 5.4.257; >= 5.10.94, < 5.10.195; >= 5.15.17, < 5.15.132; >= 4.4.300, < 4.5; >= 4.9.298, < 4.10; >= 5.16.3, < 5.17
LinuxLinux5.17

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-54266?
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: m920x: Fix a potential memory leak in m920x_i2c_xfer() 'read' is freed when it is known to be NULL, but not when a read error occurs. Revert the logic to avoid a small leak, should a m920x_read() call fail.
How severe is CVE-2023-54266?
Severity scoring for CVE-2023-54266 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2023-54266?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-54266?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST