Wind River Support Network

HomeDefectsLIN1022-19071
Fixed

LIN1022-19071 : Security Advisory - linux - CVE-2023-53696

Created: Oct 22, 2025    Updated: Oct 26, 2025
Resolved Date: Oct 26, 2025
Found In Version: 10.22.33.1
Fix Version: 10.22.33.9
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]scsi: qla2xxx: Fix memory leak in qla2x00_probe_one()[EOL][EOL]There is a memory leak reported by kmemleak:[EOL][EOL]  unreferenced object 0xffffc900003f0000 (size 12288):[EOL]    comm "modprobe", pid 19117, jiffies 4299751452 (age 42490.264s)[EOL]    hex dump (first 32 bytes):[EOL]      00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................[EOL]      00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................[EOL]    backtrace:[EOL]      [<00000000629261a8>] __vmalloc_node_range+0xe56/0x1110[EOL]      [<0000000001906886>] __vmalloc_node+0xbd/0x150[EOL]      [<000000005bb4dc34>] vmalloc+0x25/0x30[EOL]      [<00000000a2dc1194>] qla2x00_create_host+0x7a0/0xe30 [qla2xxx][EOL]      [<0000000062b14b47>] qla2x00_probe_one+0x2eb8/0xd160 [qla2xxx][EOL]      [<00000000641ccc04>] local_pci_probe+0xeb/0x1a0[EOL][EOL]The root cause is traced to an error-handling path in qla2x00_probe_one()[EOL]when the adapter "base_vha" initialize failed. The fab_scan_rp "scan.l" is[EOL]used to record the port information and it is allocated in[EOL]qla2x00_create_host(). However, it is not released in the error handling[EOL]path "probe_failed".[EOL][EOL]Fix this by freeing the memory of "scan.l" when an error occurs in the[EOL]adapter initialization process.

CVEs


Live chat
Online