{"id":"DEBIAN-CVE-2023-53078","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: scsi_dh_alua: Fix memleak for 'qdata' in alua_activate()  If alua_rtpg_queue() failed from alua_activate(), then 'qdata' is not freed, which will cause following memleak:  unreferenced object 0xffff88810b2c6980 (size 32):   comm \"kworker/u16:2\", pid 635322, jiffies 4355801099 (age 1216426.076s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     40 39 24 c1 ff ff ff ff 00 f8 ea 0a 81 88 ff ff  @9$.............   backtrace:     [\u003c0000000098f3a26d\u003e] alua_activate+0xb0/0x320     [\u003c000000003b529641\u003e] scsi_dh_activate+0xb2/0x140     [\u003c000000007b296db3\u003e] activate_path_work+0xc6/0xe0 [dm_multipath]     [\u003c000000007adc9ace\u003e] process_one_work+0x3c5/0x730     [\u003c00000000c457a985\u003e] worker_thread+0x93/0x650     [\u003c00000000cb80e628\u003e] kthread+0x1ba/0x210     [\u003c00000000a1e61077\u003e] ret_from_fork+0x22/0x30  Fix the problem by freeing 'qdata' in error path.","modified":"2026-09-15T09:03:02.455461673Z","published":"2025-05-02T16:15:26.820Z","upstream":["CVE-2023-53078"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53078"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53078.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53078.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53078.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}