CVE-2023-54064
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
In the Linux kernel, the following vulnerability has been resolved: ipmi:ssif: Fix a memory leak when scanning for an adapter The adapter scan ssif_info_find() sets info->adapter_name if the adapter info came from SMBIOS, as it's not set in that case. However, this function can be called more than once, and it will leak the adapter name if it had already been set. So check for NULL before setting it.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-54064
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-54064.html
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:2394
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| sles | affected | | |
| debian | bookworm | fixed | 6.1.55-1 |
| debian | bullseye | fixed | 5.10.197-1 |
| debian | forky | fixed | 6.5.3-1 |
| debian | sid | fixed | 6.5.3-1 |
| debian | trixie | fixed | 6.5.3-1 |
References
Verify integrity in audit chain (admin only). AS-IS.