{"id":"DEBIAN-CVE-2023-54154","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: target: core: Fix target_cmd_counter leak  The target_cmd_counter struct allocated via target_alloc_cmd_counter() is never freed, resulting in leaks across various transport types, e.g.:   unreferenced object 0xffff88801f920120 (size 96):   comm \"sh\", pid 102, jiffies 4294892535 (age 713.412s)   hex dump (first 32 bytes):     07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 38 01 92 1f 80 88 ff ff  ........8.......   backtrace:     [\u003c00000000e58a6252\u003e] kmalloc_trace+0x11/0x20     [\u003c0000000043af4b2f\u003e] target_alloc_cmd_counter+0x17/0x90 [target_core_mod]     [\u003c000000007da2dfa7\u003e] target_setup_session+0x2d/0x140 [target_core_mod]     [\u003c0000000068feef86\u003e] tcm_loop_tpg_nexus_store+0x19b/0x350 [tcm_loop]     [\u003c000000006a80e021\u003e] configfs_write_iter+0xb1/0x120     [\u003c00000000e9f4d860\u003e] vfs_write+0x2e4/0x3c0     [\u003c000000008143433b\u003e] ksys_write+0x80/0xb0     [\u003c00000000a7df29b2\u003e] do_syscall_64+0x42/0x90     [\u003c0000000053f45fb8\u003e] entry_SYSCALL_64_after_hwframe+0x6e/0xd8  Free the structure alongside the corresponding iscsit_conn / se_sess parent.","modified":"2026-09-15T08:47:31.659922267Z","published":"2025-12-24T13:16:17.407Z","upstream":["CVE-2023-54154"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54154"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.55-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54154.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54154.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54154.json"}}],"schema_version":"1.9.0"}