{"id":"DEBIAN-CVE-2023-53190","details":"In the Linux kernel, the following vulnerability has been resolved:  vxlan: Fix memory leaks in error path  The memory allocated by vxlan_vnigroup_init() is not freed in the error path, leading to memory leaks [1]. Fix by calling vxlan_vnigroup_uninit() in the error path.  The leaks can be reproduced by annotating gro_cells_init() with ALLOW_ERROR_INJECTION() and then running:   # echo \"100\" \u003e /sys/kernel/debug/fail_function/probability  # echo \"1\" \u003e /sys/kernel/debug/fail_function/times  # echo \"gro_cells_init\" \u003e /sys/kernel/debug/fail_function/inject  # printf %#x -12 \u003e /sys/kernel/debug/fail_function/gro_cells_init/retval  # ip link add name vxlan0 type vxlan dstport 4789 external vnifilter  RTNETLINK answers: Cannot allocate memory  [1] unreferenced object 0xffff88810db84a00 (size 512):   comm \"ip\", pid 330, jiffies 4295010045 (age 66.016s)   hex dump (first 32 bytes):     f8 d5 76 0e 81 88 ff ff 01 00 00 00 00 00 00 02  ..v.............     03 00 04 00 48 00 00 00 00 00 00 01 04 00 01 00  ....H...........   backtrace:     [\u003cffffffff81a3097a\u003e] kmalloc_trace+0x2a/0x60     [\u003cffffffff82f049fc\u003e] vxlan_vnigroup_init+0x4c/0x160     [\u003cffffffff82ecd69e\u003e] vxlan_init+0x1ae/0x280     [\u003cffffffff836858ca\u003e] register_netdevice+0x57a/0x16d0     [\u003cffffffff82ef67b7\u003e] __vxlan_dev_create+0x7c7/0xa50     [\u003cffffffff82ef6ce6\u003e] vxlan_newlink+0xd6/0x130     [\u003cffffffff836d02ab\u003e] __rtnl_newlink+0x112b/0x18a0     [\u003cffffffff836d0a8c\u003e] rtnl_newlink+0x6c/0xa0     [\u003cffffffff836c0ddf\u003e] rtnetlink_rcv_msg+0x43f/0xd40     [\u003cffffffff83908ce0\u003e] netlink_rcv_skb+0x170/0x440     [\u003cffffffff839066af\u003e] netlink_unicast+0x53f/0x810     [\u003cffffffff839072d8\u003e] netlink_sendmsg+0x958/0xe70     [\u003cffffffff835c319f\u003e] ____sys_sendmsg+0x78f/0xa90     [\u003cffffffff835cd6da\u003e] ___sys_sendmsg+0x13a/0x1e0     [\u003cffffffff835cd94c\u003e] __sys_sendmsg+0x11c/0x1f0     [\u003cffffffff8424da78\u003e] do_syscall_64+0x38/0x80 unreferenced object 0xffff88810e76d5f8 (size 192):   comm \"ip\", pid 330, jiffies 4295010045 (age 66.016s)   hex dump (first 32 bytes):     04 00 00 00 00 00 00 00 db e1 4f e7 00 00 00 00  ..........O.....     08 d6 76 0e 81 88 ff ff 08 d6 76 0e 81 88 ff ff  ..v.......v.....   backtrace:     [\u003cffffffff81a3162e\u003e] __kmalloc_node+0x4e/0x90     [\u003cffffffff81a0e166\u003e] kvmalloc_node+0xa6/0x1f0     [\u003cffffffff8276e1a3\u003e] bucket_table_alloc.isra.0+0x83/0x460     [\u003cffffffff8276f18b\u003e] rhashtable_init+0x43b/0x7c0     [\u003cffffffff82f04a1c\u003e] vxlan_vnigroup_init+0x6c/0x160     [\u003cffffffff82ecd69e\u003e] vxlan_init+0x1ae/0x280     [\u003cffffffff836858ca\u003e] register_netdevice+0x57a/0x16d0     [\u003cffffffff82ef67b7\u003e] __vxlan_dev_create+0x7c7/0xa50     [\u003cffffffff82ef6ce6\u003e] vxlan_newlink+0xd6/0x130     [\u003cffffffff836d02ab\u003e] __rtnl_newlink+0x112b/0x18a0     [\u003cffffffff836d0a8c\u003e] rtnl_newlink+0x6c/0xa0     [\u003cffffffff836c0ddf\u003e] rtnetlink_rcv_msg+0x43f/0xd40     [\u003cffffffff83908ce0\u003e] netlink_rcv_skb+0x170/0x440     [\u003cffffffff839066af\u003e] netlink_unicast+0x53f/0x810     [\u003cffffffff839072d8\u003e] netlink_sendmsg+0x958/0xe70     [\u003cffffffff835c319f\u003e] ____sys_sendmsg+0x78f/0xa90","modified":"2026-09-15T09:02:42.064748970Z","published":"2025-09-15T14:15:41.277Z","upstream":["CVE-2023-53190"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53190"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53190.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53190.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53190.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}