{
  "threat_severity" : "Low",
  "public_date" : "2025-12-24T00:00:00Z",
  "bugzilla" : {
    "description" : "kernel: Linux kernel KVM: Memory leak via coalesced MMIO unregistration failure",
    "id" : "2424961",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2424961"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-772",
  "details" : [ "In the Linux kernel, the following vulnerability has been resolved:\nKVM: Destroy target device if coalesced MMIO unregistration fails\nDestroy and free the target coalesced MMIO device if unregistering said\ndevice fails.  As clearly noted in the code, kvm_io_bus_unregister_dev()\ndoes not destroy the target device.\nBUG: memory leak\nunreferenced object 0xffff888112a54880 (size 64):\ncomm \"syz-executor.2\", pid 5258, jiffies 4297861402 (age 14.129s)\nhex dump (first 32 bytes):\n38 c7 67 15 00 c9 ff ff 38 c7 67 15 00 c9 ff ff  8.g.....8.g.....\ne0 c7 e1 83 ff ff ff ff 00 30 67 15 00 c9 ff ff  .........0g.....\nbacktrace:\n[<0000000006995a8a>] kmalloc include/linux/slab.h:556 [inline]\n[<0000000006995a8a>] kzalloc include/linux/slab.h:690 [inline]\n[<0000000006995a8a>] kvm_vm_ioctl_register_coalesced_mmio+0x8e/0x3d0 arch/x86/kvm/../../../virt/kvm/coalesced_mmio.c:150\n[<00000000022550c2>] kvm_vm_ioctl+0x47d/0x1600 arch/x86/kvm/../../../virt/kvm/kvm_main.c:3323\n[<000000008a75102f>] vfs_ioctl fs/ioctl.c:46 [inline]\n[<000000008a75102f>] file_ioctl fs/ioctl.c:509 [inline]\n[<000000008a75102f>] do_vfs_ioctl+0xbab/0x1160 fs/ioctl.c:696\n[<0000000080e3f669>] ksys_ioctl+0x76/0xa0 fs/ioctl.c:713\n[<0000000059ef4888>] __do_sys_ioctl fs/ioctl.c:720 [inline]\n[<0000000059ef4888>] __se_sys_ioctl fs/ioctl.c:718 [inline]\n[<0000000059ef4888>] __x64_sys_ioctl+0x6f/0xb0 fs/ioctl.c:718\n[<000000006444fa05>] do_syscall_64+0x9f/0x4e0 arch/x86/entry/common.c:290\n[<000000009a4ed50b>] entry_SYSCALL_64_after_hwframe+0x49/0xbe\nBUG: leak checking failed", "A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. This vulnerability occurs when the unregistration of a coalesced Memory-Mapped I/O (MMIO) device fails, leading to a memory leak. A local attacker could exploit this flaw to consume system memory, potentially causing a Denial of Service (DoS) condition." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2023-11-07T00:00:00Z",
    "advisory" : "RHSA-2023:6583",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "kernel-0:5.14.0-362.8.1.el9_3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2023-11-07T00:00:00Z",
    "advisory" : "RHSA-2023:6583",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "kernel-0:5.14.0-362.8.1.el9_3"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "kernel",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "kernel-rt",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-54024\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-54024\nhttps://lore.kernel.org/linux-cve-announce/2025122434-CVE-2023-54024-30aa@gregkh/T" ],
  "name" : "CVE-2023-54024",
  "csaw" : false
}