Home

Description

In the Linux kernel, the following vulnerability has been resolved: xen: speed up grant-table reclaim When a grant entry is still in use by the remote domain, Linux must put it on a deferred list. Normally, this list is very short, because the PV network and block protocols expect the backend to unmap the grant first. However, Qubes OS's GUI protocol is subject to the constraints of the X Window System, and as such winds up with the frontend unmapping the window first. As a result, the list can grow very large, resulting in a massive memory leak and eventual VM freeze. To partially solve this problem, make the number of entries that the VM will attempt to free at each iteration tunable. The default is still 10, but it can be overridden via a module parameter. This is Cc: stable because (when combined with appropriate userspace changes) it fixes a severe performance and stability problem for Qubes OS users.

PUBLISHED Reserved 2025-12-24 | Published 2025-12-24 | Updated 2025-12-24 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before cd1a8952ff529adc210e62306849fd6f256608c0
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before c76d96c555895ac602c1587b001e5cf656abc371
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before c04e9894846c663f3278a414f34416e6e45bbe68
affected

Default status
affected

6.1.43 (semver)
unaffected

6.4.8 (semver)
unaffected

6.5 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/cd1a8952ff529adc210e62306849fd6f256608c0

git.kernel.org/...c/c76d96c555895ac602c1587b001e5cf656abc371

git.kernel.org/...c/c04e9894846c663f3278a414f34416e6e45bbe68

cve.org (CVE-2023-54081)

nvd.nist.gov (CVE-2023-54081)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.