cbcvebase.
CVE-2023-54143
published 2025-12-24

CVE-2023-54143: In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: fix resource leaks in vdec_msg_queue_init() If we encounter any…

PriorityP418
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: fix resource leaks in vdec_msg_queue_init() If we encounter any error in the vdec_msg_queue_init() then we need to set "msg_queue->wdma_addr.size = 0;". Normally, this is done inside the vdec_msg_queue_deinit() function. However, if the first call to allocate &msg_queue->wdma_addr fails, then the vdec_msg_queue_deinit() function is a no-op. For that situation, just set the size to zero explicitly and return. There were two other error paths which did not clean up before returning. Change those error paths to goto mem_alloc_err.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= b199fe46f35c57a415acd4d5295b0f4e35048c11 < 858322c409e0aba8f70810d23f35c482744f007c858322c409e0aba8f70810d23f35c482744f007c
linuxlinux>= b199fe46f35c57a415acd4d5295b0f4e35048c11 < b7dbc27301f560c3b915235c53383155b3512083b7dbc27301f560c3b915235c53383155b3512083
linuxlinux>= b199fe46f35c57a415acd4d5295b0f4e35048c11 < 451dc187cadd47771e5d9434fe220fad7be84057451dc187cadd47771e5d9434fe220fad7be84057
linuxlinux>= b199fe46f35c57a415acd4d5295b0f4e35048c11 < cf10b0bb503c974ba049d6f888b21178be20a962cf10b0bb503c974ba049d6f888b21178be20a962
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 5.18.0 < 6.1.536.1.53
linuxlinux_kernel>= 6.2.0 < 6.4.166.4.16
linuxlinux_kernel>= 6.5.0 < 6.5.36.5.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.