cbcvebase.
CVE-2023-53324
published 2025-09-16

CVE-2023-53324: In the Linux kernel, the following vulnerability has been resolved: drm/msm/mdp5: Don't leak some plane state Apparently no one noticed that mdp5 plane states…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/msm/mdp5: Don't leak some plane state Apparently no one noticed that mdp5 plane states leak like a sieve ever since we introduced plane_state->commit refcount a few years ago in 21a01abbe32a ("drm/atomic: Fix freeing connector/plane state too early by tracking commits, v3.") Fix it by using the right helpers. Patchwork: https://patchwork.freedesktop.org/patch/551236/

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < 7fc11a830b2eb07a0e3c6f917e5e636df6fc5d4c7fc11a830b2eb07a0e3c6f917e5e636df6fc5d4c
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < b8a61df6f40448cf46611f7af05b00970d08d620b8a61df6f40448cf46611f7af05b00970d08d620
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < 815e42029f6e1e762898079f85546d6a0391ab95815e42029f6e1e762898079f85546d6a0391ab95
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < c0b1eee648702e04f1005d451f9689575b7f52edc0b1eee648702e04f1005d451f9689575b7f52ed
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < 2965015006ef18ca96d2eab9ebe6bca884c632912965015006ef18ca96d2eab9ebe6bca884c63291
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < 5b0dd3a102f64996598bd1e8d8388848a7c561bc5b0dd3a102f64996598bd1e8d8388848a7c561bc
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < 12dfd02cbd1a678fbd66be0c2f79d5299c4921a912dfd02cbd1a678fbd66be0c2f79d5299c4921a9
linuxlinux>= 21a01abbe32a3cbeb903378a24e504bfd9fe0648 < fd0ad3b2365c1c58aa5a761c18efc4817193beb6fd0ad3b2365c1c58aa5a761c18efc4817193beb6
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 4.15 < 4.19.2954.19.295
linuxlinux_kernel>= 4.20 < 5.4.2575.4.257
linuxlinux_kernel>= 5.11 < 5.15.1325.15.132
linuxlinux_kernel>= 5.16 < 6.1.536.1.53
linuxlinux_kernel>= 5.5 < 5.10.1955.10.195
linuxlinux_kernel>= 6.2 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.