cbcvebase.
CVE-2023-54097
published 2025-12-24

CVE-2023-54097: In the Linux kernel, the following vulnerability has been resolved: regulator: stm32-pwr: fix of_iomap leak Smatch reports: drivers/regulator/stm32-pwr.c:166…

PriorityP421low5.5
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: regulator: stm32-pwr: fix of_iomap leak Smatch reports: drivers/regulator/stm32-pwr.c:166 stm32_pwr_regulator_probe() warn: 'base' from of_iomap() not released on lines: 151,166. In stm32_pwr_regulator_probe(), base is not released when devm_kzalloc() fails to allocate memory or devm_regulator_register() fails to register a new regulator device, which may cause a leak. To fix this issue, replace of_iomap() with devm_platform_ioremap_resource(). devm_platform_ioremap_resource() is a specialized function for platform devices. It allows 'base' to be automatically released whether the probe function succeeds or fails. Besides, use IS_ERR(base) instead of !base as the return value of devm_platform_ioremap_resource() can either be a pointer to the remapped memory or an ERR_PTR() encoded error code if the operation fails.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < 824683dbec234a01bd49a0589ee3323594a6f4cf824683dbec234a01bd49a0589ee3323594a6f4cf
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < dfce9bb3517a78507cf96f9b83948d0b81338afadfce9bb3517a78507cf96f9b83948d0b81338afa
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < ad6481f49fb2c703efa3a929643934f24b666d6aad6481f49fb2c703efa3a929643934f24b666d6a
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < f25994f7a9ad53eb756bc4869497c3ebe281ad5ef25994f7a9ad53eb756bc4869497c3ebe281ad5e
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < c091bb49b3233307c7af73dae888f0799752af3dc091bb49b3233307c7af73dae888f0799752af3d
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < 0ad07e02be0d3f0d554653382ffe53ae4879378d0ad07e02be0d3f0d554653382ffe53ae4879378d
linuxlinux>= dc62f951a6a8490bcccc7b6de36cd85bd57be740 < c4a413e56d16a2ae84e6d8992f215c4dcc7fac20c4a413e56d16a2ae84e6d8992f215c4dcc7fac20
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 5.2.0 < 5.4.2435.4.243
linuxlinux_kernel>= 5.5.0 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.