{"id":"DEBIAN-CVE-2023-53696","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: qla2xxx: Fix memory leak in qla2x00_probe_one()  There is a memory leak reported by kmemleak:    unreferenced object 0xffffc900003f0000 (size 12288):     comm \"modprobe\", pid 19117, jiffies 4299751452 (age 42490.264s)     hex dump (first 32 bytes):       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     backtrace:       [\u003c00000000629261a8\u003e] __vmalloc_node_range+0xe56/0x1110       [\u003c0000000001906886\u003e] __vmalloc_node+0xbd/0x150       [\u003c000000005bb4dc34\u003e] vmalloc+0x25/0x30       [\u003c00000000a2dc1194\u003e] qla2x00_create_host+0x7a0/0xe30 [qla2xxx]       [\u003c0000000062b14b47\u003e] qla2x00_probe_one+0x2eb8/0xd160 [qla2xxx]       [\u003c00000000641ccc04\u003e] local_pci_probe+0xeb/0x1a0  The root cause is traced to an error-handling path in qla2x00_probe_one() when the adapter \"base_vha\" initialize failed. The fab_scan_rp \"scan.l\" is used to record the port information and it is allocated in qla2x00_create_host(). However, it is not released in the error handling path \"probe_failed\".  Fix this by freeing the memory of \"scan.l\" when an error occurs in the adapter initialization process.","modified":"2026-09-15T08:47:52.076184089Z","published":"2025-10-22T14:15:44.113Z","upstream":["CVE-2023-53696"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53696"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53696.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53696.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53696.json"}}],"schema_version":"1.9.0"}