« Volver al listado

CVE-2023-54208

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

media: ov5675: Fix memleak in ov5675_init_controls()

There is a kmemleak when testing the media/i2c/ov5675.c with bpf mock device:

ov5675_init_controls() won't clean all the allocated resources in fail path, which may causes the memleaks. Add v4l2_ctrl_handler_free() to prevent memleak.

Detalles técnicos trazas, registros y código del informe original
AssertionError: unreferenced object 0xffff888107362160 (size 16):
  comm "python3", pid 277, jiffies 4294832798 (age 20.722s)
  hex dump (first 16 bytes):
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
  backtrace:
    [<00000000abe7d67c>] __kmalloc_node+0x44/0x1b0
    [<000000008a725aac>] kvmalloc_node+0x34/0x180
    [<000000009a53cd11>] v4l2_ctrl_handler_init_class+0x11d/0x180
[videodev]
    [<0000000055b46db0>] ov5675_probe+0x38b/0x897 [ov5675]
    [<00000000153d886c>] i2c_device_probe+0x28d/0x680
    [<000000004afb7e8f>] really_probe+0x17c/0x3f0
    [<00000000ff2f18e4>] __driver_probe_device+0xe3/0x170
    [<000000000a001029>] driver_probe_device+0x49/0x120
    [<00000000e39743c7>] __device_attach_driver+0xf7/0x150
    [<00000000d32fd070>] bus_for_each_drv+0x114/0x180
    [<000000009083ac41>] __device_attach+0x1e5/0x2d0
    [<0000000015b4a830>] bus_probe_device+0x126/0x140
    [<000000007813deaf>] device_add+0x810/0x1130
    [<000000007becb867>] i2c_new_client_device+0x386/0x540
    [<000000007f9cf4b4>] of_i2c_register_device+0xf1/0x110
    [<00000000ebfdd032>] of_i2c_notify+0xfc/0x1f0

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54208",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "086a80b842bcb621d6c4eedad20683f1f674d0c2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "bcae9115a163198dce9126aa8bedc1c007ec30ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "ba54908ae8225d58f1830edb394d4153bcb7d0aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "49b849824b9862f177fc77fc92ef95ec54566ecf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "7a36a6be694df87d019663863b922913947b42af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bf27502b1f3bf8095bf81736e506d354a2ce9ec4",
              "lessThan": "dd74ed6c213003533e3abf4c204374ef01d86978",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/media/i2c/ov5675.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.235",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.173",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.99",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.16",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/media/i2c/ov5675.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-30T13:16:08.977",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/086a80b842bcb621d6c4eedad20683f1f674d0c2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/49b849824b9862f177fc77fc92ef95ec54566ecf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a36a6be694df87d019663863b922913947b42af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba54908ae8225d58f1830edb394d4153bcb7d0aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bcae9115a163198dce9126aa8bedc1c007ec30ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd74ed6c213003533e3abf4c204374ef01d86978",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ov5675: Fix memleak in ov5675_init_controls()\n\nThere is a kmemleak when testing the media/i2c/ov5675.c with bpf mock\ndevice:\n\nAssertionError: unreferenced object 0xffff888107362160 (size 16):\n  comm \"python3\", pid 277, jiffies 4294832798 (age 20.722s)\n  hex dump (first 16 bytes):\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n  backtrace:\n    [<00000000abe7d67c>] __kmalloc_node+0x44/0x1b0\n    [<000000008a725aac>] kvmalloc_node+0x34/0x180\n    [<000000009a53cd11>] v4l2_ctrl_handler_init_class+0x11d/0x180\n[videodev]\n    [<0000000055b46db0>] ov5675_probe+0x38b/0x897 [ov5675]\n    [<00000000153d886c>] i2c_device_probe+0x28d/0x680\n    [<000000004afb7e8f>] really_probe+0x17c/0x3f0\n    [<00000000ff2f18e4>] __driver_probe_device+0xe3/0x170\n    [<000000000a001029>] driver_probe_device+0x49/0x120\n    [<00000000e39743c7>] __device_attach_driver+0xf7/0x150\n    [<00000000d32fd070>] bus_for_each_drv+0x114/0x180\n    [<000000009083ac41>] __device_attach+0x1e5/0x2d0\n    [<0000000015b4a830>] bus_probe_device+0x126/0x140\n    [<000000007813deaf>] device_add+0x810/0x1130\n    [<000000007becb867>] i2c_new_client_device+0x386/0x540\n    [<000000007f9cf4b4>] of_i2c_register_device+0xf1/0x110\n    [<00000000ebfdd032>] of_i2c_notify+0xfc/0x1f0\n\nov5675_init_controls() won't clean all the allocated resources in fail\npath, which may causes the memleaks. Add v4l2_ctrl_handler_free() to\nprevent memleak."
    }
  ],
  "lastModified": "2026-06-17T06:47:01.133",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}