CVE-2023-54230
published 2025-12-30CVE-2023-54230: In the Linux kernel, the following vulnerability has been resolved: amba: bus: fix refcount leak commit 5de1540b7bc4 ("drivers/amba: create devices from device…
PriorityP419low3.3
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 94e398df32e850f26828690ee62f7441979583cc | 94e398df32e850f26828690ee62f7441979583cc |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 9062ce0ccbd82fbe81cc839a512c0ad90847e01c | 9062ce0ccbd82fbe81cc839a512c0ad90847e01c |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 03db4fe7917bb160eeccf3968835475fa32b7e10 | 03db4fe7917bb160eeccf3968835475fa32b7e10 |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 9baf2278b3eed2c50112169121257d8a6ee0606c | 9baf2278b3eed2c50112169121257d8a6ee0606c |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 4f1807fddd9bf175ee5e14fffc6b6106e4b297ef | 4f1807fddd9bf175ee5e14fffc6b6106e4b297ef |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 81ff633a88be2482c163d3acd2801d501261ce6a | 81ff633a88be2482c163d3acd2801d501261ce6a |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 206fadb7278ceac7593dd0b945a77b9df856a674 | 206fadb7278ceac7593dd0b945a77b9df856a674 |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < 8b60a706166de5de82314494704c2419e7657bf8 | 8b60a706166de5de82314494704c2419e7657bf8 |
| linux | linux | >= 5de1540b7bc4c23470f86add1e517be41e7fefe2 < e312cbdc11305568554a9e18a2ea5c2492c183f3 | e312cbdc11305568554a9e18a2ea5c2492c183f3 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 3.1.0 < 4.14.326 | 4.14.326 |
| linux | linux_kernel | >= 4.15.0 < 4.19.295 | 4.19.295 |
| linux | linux_kernel | >= 4.20.0 < 5.4.257 | 5.4.257 |
| linux | linux_kernel | >= 5.11.0 < 5.15.132 | 5.15.132 |
| linux | linux_kernel | >= 5.16.0 < 6.1.53 | 6.1.53 |
| linux | linux_kernel | >= 5.5.0 < 5.10.195 | 5.10.195 |
| linux | linux_kernel | >= 6.2.0 < 6.4.16 | 6.4.16 |
| linux | linux_kernel | >= 6.5.0 < 6.5.3 | 6.5.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.5.2 amba of_node reference count (Nessus ID 280799 / WID-SEC-2025-2941)
vuldb·2026-04-27
CVE-2023-54230 [CRITICAL] Linux Kernel up to 6.5.2 amba of_node reference count (Nessus ID 280799 / WID-SEC-2025-2941)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.5.2. This affects the function of_node of the component amba. The manipulation results in improper update of reference count.
This vulnerability is cataloged as CVE-2023-54230. The attack must originate from the local network. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-9qf5-c4fq-57p4: In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices
ghsa_unreviewed·2025-12-30
CVE-2023-54230 GHSA-9qf5-c4fq-57p4: In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
OSV
amba: bus: fix refcount leak
osv·2025-12-30
CVE-2023-54230 amba: bus: fix refcount leak
amba: bus: fix refcount leak
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
OSV
CVE-2023-54230: In the Linux kernel, the following vulnerability has been resolved: amba: bus: fix refcount leak commit 5de1540b7bc4 ("drivers/amba: create devices fr
osv·2025-12-30
CVE-2023-54230 CVE-2023-54230: In the Linux kernel, the following vulnerability has been resolved: amba: bus: fix refcount leak commit 5de1540b7bc4 ("drivers/amba: create devices fr
In the Linux kernel, the following vulnerability has been resolved: amba: bus: fix refcount leak commit 5de1540b7bc4 ("drivers/amba: create devices from device tree") increases the refcount of of_node, but not releases it in amba_device_release, so there is refcount leak. By using of_node_put to avoid refcount leak.
Red Hat
kernel: amba: bus: fix refcount leak
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2023-54230 [LOW] CWE-911 kernel: amba: bus: fix refcount leak
kernel: amba: bus: fix refcount leak
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
A reference count leak was found in the ARM AMBA bus driver. When AMBA devices are created from device tree, the of_node reference count is incremented but never decremented in amba_device_release(), causing gradual memory leaks.
Statement: This primarily affects ARM/ARM64 systems using AMBA peripherals. The leak is small per device and accumulates slowly over device add/remove cycles. Normal system operation without frequent device chang
Debian
CVE-2023-54230: linux - In the Linux kernel, the following vulnerability has been resolved: amba: bus: ...
vendor_debian·2023
CVE-2023-54230 CVE-2023-54230: linux - In the Linux kernel, the following vulnerability has been resolved: amba: bus: ...
In the Linux kernel, the following vulnerability has been resolved: amba: bus: fix refcount leak commit 5de1540b7bc4 ("drivers/amba: create devices from device tree") increases the refcount of of_node, but not releases it in amba_device_release, so there is refcount leak. By using of_node_put to avoid refcount leak.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54230 CVE-2023-54230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54230 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-debug-kvm
kernel-debug
Sources
NVD
Debian 11, 12, 13, 14 Has F
Bugzilla
CVE-2023-54230 kernel: amba: bus: fix refcount leak
bugzilla·2025-12-30
CVE-2023-54230 [LOW] CVE-2023-54230 kernel: amba: bus: fix refcount leak
CVE-2023-54230 kernel: amba: bus: fix refcount leak
In the Linux kernel, the following vulnerability has been resolved:
amba: bus: fix refcount leak
commit 5de1540b7bc4 ("drivers/amba: create devices from device tree")
increases the refcount of of_node, but not releases it in
amba_device_release, so there is refcount leak. By using of_node_put
to avoid refcount leak.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123030-CVE-2023-54230-914e@gregkh/T
https://git.kernel.org/stable/c/03db4fe7917bb160eeccf3968835475fa32b7e10https://git.kernel.org/stable/c/206fadb7278ceac7593dd0b945a77b9df856a674https://git.kernel.org/stable/c/4f1807fddd9bf175ee5e14fffc6b6106e4b297efhttps://git.kernel.org/stable/c/81ff633a88be2482c163d3acd2801d501261ce6ahttps://git.kernel.org/stable/c/8b60a706166de5de82314494704c2419e7657bf8https://git.kernel.org/stable/c/9062ce0ccbd82fbe81cc839a512c0ad90847e01chttps://git.kernel.org/stable/c/94e398df32e850f26828690ee62f7441979583cchttps://git.kernel.org/stable/c/9baf2278b3eed2c50112169121257d8a6ee0606chttps://git.kernel.org/stable/c/e312cbdc11305568554a9e18a2ea5c2492c183f3
2025-12-30
Published