NONE · 0

CVE-2023-54146

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freein...

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freeing image->elf_headers in the error path of crash_load_segments() is not needed because kimage_file_post_load_cleanup() will take care of that later. And not clearing it could result in a double-free. Drop the superfluous vfree() call at the error path of crash_load_segments().

References

FAQ

What is CVE-2023-54146?

CVE-2023-54146 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Fix double-free of elf header buffer After b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"), freein...

How severe is CVE-2023-54146?

CVSS scoring is not yet available for CVE-2023-54146. Check NVD for updates.

Is there a patch for CVE-2023-54146?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.