CVE-2023-54146

Source
https://cve.org/CVERecord?id=CVE-2023-54146
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54146.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-54146
Downstream
Related
Published
2025-12-24T13:06:58.904Z
Modified
2026-03-20T12:33:28.262800Z
Summary
x86/kexec: Fix double-free of elf header buffer
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/kexec: Fix double-free of elf header buffer

After

b3e34a47f989 ("x86/kexec: fix memory leak of elf header buffer"),

freeing image->elfheaders in the error path of crashloadsegments() is not needed because kimagefilepostload_cleanup() will take care of that later. And not clearing it could result in a double-free.

Drop the superfluous vfree() call at the error path of crashloadsegments().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54146.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
23cf39dccf7653650701a6f39b119e9116a27f1a
Fixed
4c71a552b97fb4f46eb300224434fe56fcf4f254
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8765a423a87d74ef24ea02b43b2728fe4039f248
Fixed
554a880a1fff46dd5a355dec21cd77d542a0ddf2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b3e34a47f98974d0844444c5121aaff123004e57
Fixed
fbdbf8ac333d3d47c0d9ea81d7d445654431d100
Fixed
5bd3c7abeb69fb4133418b846a1c6dc11313d6f0
Fixed
d00dd2f2645dca04cf399d8fc692f3f69b6dd996
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
115ee42a4c2f26ba2b4ace2668a3f004621f6833
Last affected
f675e3a9189d84a9324ab45b0cb19906c2bc8fcb

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54146.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.87
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.19
Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54146.json"