CVE-2023-54190
published 2025-12-30CVE-2023-54190: In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() calls…
PriorityP418low5.5
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node() calls class_find_device(), it will take
the reference, use the put_device() to drop the reference when not need
anymore.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 699a8c7c4bd376aee4808e6272188319e900c8af < 1d6101d9222e1ca8c01b3fa9ebf0dcf7bcd82564 | 1d6101d9222e1ca8c01b3fa9ebf0dcf7bcd82564 |
| linux | linux | >= 699a8c7c4bd376aee4808e6272188319e900c8af < 690efcb5827c3bacbf1de90cd14907b91bf8cb7b | 690efcb5827c3bacbf1de90cd14907b91bf8cb7b |
| linux | linux | >= 699a8c7c4bd376aee4808e6272188319e900c8af < d880981b82223f9bf128dfdd2424abb0c658f345 | d880981b82223f9bf128dfdd2424abb0c658f345 |
| linux | linux | >= 699a8c7c4bd376aee4808e6272188319e900c8af < ddf3e82164afd9381b1d52c9f00b3878f7b6d308 | ddf3e82164afd9381b1d52c9f00b3878f7b6d308 |
| linux | linux | >= 699a8c7c4bd376aee4808e6272188319e900c8af < da1afe8e6099980fe1e2fd7436dca284af9d3f29 | da1afe8e6099980fe1e2fd7436dca284af9d3f29 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.6.0 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2.0 < 6.2.3 | 6.2.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: Kernel: Denial of Service via reference count leak in LED core
vendor_redhat·2025-12-30·CVSS 5.5
CVE-2023-54190 [LOW] CWE-772 kernel: Kernel: Denial of Service via reference count leak in LED core
kernel: Kernel: Denial of Service via reference count leak in LED core
In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node() calls class_find_device(), it will take
the reference, use the put_device() to drop the reference when not need
anymore.
A flaw was found in the Linux kernel's LED core component. A local user could exploit a reference count leak in the `of_led_get()` function. This vulnerability can lead to a denial of service (DoS) due to resource exhaustion.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise
Debian
CVE-2023-54190: linux - In the Linux kernel, the following vulnerability has been resolved: leds: led-c...
vendor_debian·2023
CVE-2023-54190 CVE-2023-54190: linux - In the Linux kernel, the following vulnerability has been resolved: leds: led-c...
In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() calls class_find_device(), it will take the reference, use the put_device() to drop the reference when not need anymore.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
GHSA
GHSA-964v-hgf6-j872: In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node()
ghsa_unreviewed·2025-12-30
CVE-2023-54190 GHSA-964v-hgf6-j872: In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node()
In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node() calls class_find_device(), it will take
the reference, use the put_device() to drop the reference when not need
anymore.
OSV
CVE-2023-54190: In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() c
osv·2025-12-30
CVE-2023-54190 CVE-2023-54190: In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() c
In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() calls class_find_device(), it will take the reference, use the put_device() to drop the reference when not need anymore.
OSV
leds: led-core: Fix refcount leak in of_led_get()
osv·2025-12-30
CVE-2023-54190 leds: led-core: Fix refcount leak in of_led_get()
leds: led-core: Fix refcount leak in of_led_get()
In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node() calls class_find_device(), it will take
the reference, use the put_device() to drop the reference when not need
anymore.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1d6101d9222e1ca8c01b3fa9ebf0dcf7bcd82564https://git.kernel.org/stable/c/690efcb5827c3bacbf1de90cd14907b91bf8cb7bhttps://git.kernel.org/stable/c/d880981b82223f9bf128dfdd2424abb0c658f345https://git.kernel.org/stable/c/da1afe8e6099980fe1e2fd7436dca284af9d3f29https://git.kernel.org/stable/c/ddf3e82164afd9381b1d52c9f00b3878f7b6d308
2025-12-30
Published