cbcvebase.
CVE-2023-54208
published 2025-12-30

CVE-2023-54208: In the Linux kernel, the following vulnerability has been resolved: media: ov5675: Fix memleak in ov5675_init_controls() There is a kmemleak when testing the…

PriorityP419
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: media: ov5675: Fix memleak in ov5675_init_controls() There is a kmemleak when testing the media/i2c/ov5675.c with bpf mock device: AssertionError: unreferenced object 0xffff888107362160 (size 16): comm "python3", pid 277, jiffies 4294832798 (age 20.722s) hex dump (first 16 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc_node+0x44/0x1b0 [] kvmalloc_node+0x34/0x180 [] v4l2_ctrl_handler_init_class+0x11d/0x180 [videodev] [] ov5675_probe+0x38b/0x897 [ov5675] [] i2c_device_probe+0x28d/0x680 [] really_probe+0x17c/0x3f0 [] __driver_probe_device+0xe3/0x170 [] driver_probe_device+0x49/0x120 [] __device_attach_driver+0xf7/0x150 [] bus_for_each_drv+0x114/0x180 [] __device_attach+0x1e5/0x2d0 [] bus_probe_device+0x126/0x140 [] device_add+0x810/0x1130 [] i2c_new_client_device+0x386/0x540 [] of_i2c_register_device+0xf1/0x110 [] of_i2c_notify+0xfc/0x1f0 ov5675_init_controls() won't clean all the allocated resources in fail path, which may causes the memleaks. Add v4l2_ctrl_handler_free() to prevent memleak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < 086a80b842bcb621d6c4eedad20683f1f674d0c2086a80b842bcb621d6c4eedad20683f1f674d0c2
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < bcae9115a163198dce9126aa8bedc1c007ec30edbcae9115a163198dce9126aa8bedc1c007ec30ed
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < ba54908ae8225d58f1830edb394d4153bcb7d0aaba54908ae8225d58f1830edb394d4153bcb7d0aa
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < 49b849824b9862f177fc77fc92ef95ec54566ecf49b849824b9862f177fc77fc92ef95ec54566ecf
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < 7a36a6be694df87d019663863b922913947b42af7a36a6be694df87d019663863b922913947b42af
linuxlinux>= bf27502b1f3bf8095bf81736e506d354a2ce9ec4 < dd74ed6c213003533e3abf4c204374ef01d86978dd74ed6c213003533e3abf4c204374ef01d86978
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 5.11.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 5.4.0 < 5.4.2355.4.235
linuxlinux_kernel>= 5.5.0 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2.0 < 6.2.36.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.