{"id":"DEBIAN-CVE-2023-54115","details":"In the Linux kernel, the following vulnerability has been resolved:  pcmcia: rsrc_nonstatic: Fix memory leak in nonstatic_release_resource_db()  When nonstatic_release_resource_db() frees all resources associated with an PCMCIA socket, it forgets to free socket_data too, causing a memory leak observable with kmemleak:  unreferenced object 0xc28d1000 (size 64):   comm \"systemd-udevd\", pid 297, jiffies 4294898478 (age 194.484s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 f0 85 0e c3 00 00 00 00  ................     00 00 00 00 0c 10 8d c2 00 00 00 00 00 00 00 00  ................   backtrace:     [\u003cffda4245\u003e] __kmem_cache_alloc_node+0x2d7/0x4a0     [\u003c7e51f0c8\u003e] kmalloc_trace+0x31/0xa4     [\u003cd52b4ca0\u003e] nonstatic_init+0x24/0x1a4 [pcmcia_rsrc]     [\u003ca2f13e08\u003e] pcmcia_register_socket+0x200/0x35c [pcmcia_core]     [\u003ca728be1b\u003e] yenta_probe+0x4d8/0xa70 [yenta_socket]     [\u003cc48fac39\u003e] pci_device_probe+0x99/0x194     [\u003c84b7c690\u003e] really_probe+0x181/0x45c     [\u003c8060fe6e\u003e] __driver_probe_device+0x75/0x1f4     [\u003cb9b76f43\u003e] driver_probe_device+0x28/0xac     [\u003c648b766f\u003e] __driver_attach+0xeb/0x1e4     [\u003c6e9659eb\u003e] bus_for_each_dev+0x61/0xb4     [\u003c25a669f3\u003e] driver_attach+0x1e/0x28     [\u003cd8671d6b\u003e] bus_add_driver+0x102/0x20c     [\u003cdf0d323c\u003e] driver_register+0x5b/0x120     [\u003c942cd8a4\u003e] __pci_register_driver+0x44/0x4c     [\u003ce536027e\u003e] __UNIQUE_ID___addressable_cleanup_module188+0x1c/0xfffff000 [iTCO_vendor_support]  Fix this by freeing socket_data too.  Tested on a Acer Travelmate 4002WLMi by manually binding/unbinding the yenta_cardbus driver (yenta_socket).","modified":"2026-09-15T08:47:27.133713083Z","published":"2025-12-24T13:16:13.427Z","upstream":["CVE-2023-54115"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54115"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54115.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54115.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54115.json"}}],"schema_version":"1.9.0"}