CVE-2023-54190 — Missing Release of Resource after Effective Lifetime in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 92.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node() calls class_find_device(), it will take
the reference, use the put_device() to drop the reference when not need
anymore.
Affected Packages4 packages
▶CVEListV5linux/linux699a8c7c4bd376aee4808e6272188319e900c8af — 1d6101d9222e1ca8c01b3fa9ebf0dcf7bcd82564+5
🔴Vulnerability Details
3GHSA▶
GHSA-964v-hgf6-j872: In the Linux kernel, the following vulnerability has been resolved:
leds: led-core: Fix refcount leak in of_led_get()
class_find_device_by_of_node()↗2025-12-30
OSV▶
CVE-2023-54190: In the Linux kernel, the following vulnerability has been resolved: leds: led-core: Fix refcount leak in of_led_get() class_find_device_by_of_node() c↗2025-12-30