caif: fix memory leak in cfctrl_linkup_request()
Published Sep 16, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.14%
Description
When linktype is unknown or kzalloc failed in cfctrl_linkup_request(), pkt is not released. Add release process to error path.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.35StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.35
- Version 4.14.303StatusunaffectedConstraints<=4.14.*
- Version 4.19.270StatusunaffectedConstraints<=4.19.*
- Version 5.10.163StatusunaffectedConstraints<=5.10.*
- Version 5.15.87StatusunaffectedConstraints<=5.15.*
- Version 5.4.229StatusunaffectedConstraints<=5.4.*
- Version 6.0.19StatusunaffectedConstraints<=6.0.*
- Version 6.1.5StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.35 · < 4.14.303
- ≥ 4.15 · < 4.19.270
- ≥ 4.20 · < 5.4.229
- ≥ 5.5 · < 5.10.163
- ≥ 5.11 · < 5.15.87
- ≥ 5.16 · < 6.0.19
- ≥ 6.1 · < 6.1.5
- 6.2
- 6.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2023-53330 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395868 Issue Tracking
- https://git.kernel.org/stable/c/1dddeceb26002cfea4c375e92ac6498768dc7349 Patch
- https://git.kernel.org/stable/c/33df9c5d5e2a18c70f5f5f3c2757d654c1b6ffa3 Patch
- https://git.kernel.org/stable/c/3acf3783a84cbdf0c9f8cf2f32ee9c49af93a2da Patch
- https://git.kernel.org/stable/c/3ad47c8aa5648226184415e4a0cb1bf67ffbfd48 Patch
- https://git.kernel.org/stable/c/84b2cc7b36b7f6957d307fb3d01603f93cb2d655 Patch
- https://git.kernel.org/stable/c/badea57569db04b010e922e29a7aaf40a979a70b Patch
- https://git.kernel.org/stable/c/dc1bc903970bdf63ca40ab923d3ccb765da9a8d9 Patch
- https://git.kernel.org/stable/c/fe69230f05897b3de758427b574fc98025dfc907 Patch
- https://lore.kernel.org/linux-cve-announce/2025091645-CVE-2023-53330-8d89@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53330
- https://www.cve.org/CVERecord?id=CVE-2023-53330
Change history (0)
No recorded changes yet.