Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53324— drm/msm/mdp5: Don't leak some plane state

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未正确释放平面状态,可能导致内存泄漏。

AI Predicted 5.9 Difficulty: Easy EPSS 0.14% · P4

Possible ATT&CK Techniques 2 AI

T1499 · Endpoint Denial of Service T1562

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 21a01abbe32a3cbeb903378a24e504bfd9fe0648< 7fc11a830b2eb07a0e3c6f917e5e636df6fc5d4c affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< b8a61df6f40448cf46611f7af05b00970d08d620 affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< 815e42029f6e1e762898079f85546d6a0391ab95 affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< c0b1eee648702e04f1005d451f9689575b7f52ed affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< 2965015006ef18ca96d2eab9ebe6bca884c63291 affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< 5b0dd3a102f64996598bd1e8d8388848a7c561bc affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< 12dfd02cbd1a678fbd66be0c2f79d5299c4921a9 affected
21a01abbe32a3cbeb903378a24e504bfd9fe0648< fd0ad3b2365c1c58aa5a761c18efc4817193beb6 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-53324

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/msm/mdp5: Don't leak some plane state
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/msm/mdp5: Don't leak some plane state Apparently no one noticed that mdp5 plane states leak like a sieve ever since we introduced plane_state->commit refcount a few years ago in 21a01abbe32a ("drm/atomic: Fix freeing connector/plane state too early by tracking commits, v3.") Fix it by using the right helpers. Patchwork: https://patchwork.freedesktop.org/patch/551236/
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未正确释放平面状态,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 21a01abbe32a3cbeb903378a24e504bfd9fe0648 ~ 7fc11a830b2eb07a0e3c6f917e5e636df6fc5d4c -
Linux Linux 4.15 -

II. Public POCs for CVE-2023-53324

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53324

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-16 · 115 CVEs total

CVE-2022-50350 9.8 CRITICAL scsi: target: iscsi: Fix a race condition between login_work and the login thread
CVE-2023-53297 8.8 HIGH Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp
CVE-2025-39806 8.8 HIGH HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
CVE-2025-39827 8.8 HIGH net: rose: include node references in rose_neigh refcount
CVE-2025-39826 8.8 HIGH net: rose: convert 'use' field to refcount_t
CVE-2023-53322 8.8 HIGH scsi: qla2xxx: Wait for io return on terminate rport
CVE-2023-53305 8.8 HIGH Bluetooth: L2CAP: Fix use-after-free
CVE-2023-53315 8.8 HIGH wifi: ath11k: Fix SKB corruption in REO destination ring
CVE-2025-39809 8.4 HIGH HID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd ICRS/ISUB length
CVE-2023-53333 8.2 HIGH netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one
CVE-2025-39821 7.8 HIGH perf: Avoid undefined behavior from stopping/starting inactive events
CVE-2025-39810 7.8 HIGH bnxt_en: Fix memory corruption when FW resources change during ifdown
CVE-2022-50341 7.8 HIGH cifs: fix oops during encryption
CVE-2023-53311 7.8 HIGH nilfs2: fix use-after-free of nilfs_root in dirtying inodes via iput
CVE-2025-39815 7.8 HIGH RISC-V: KVM: fix stack overrun when loading vlenb
CVE-2023-53314 7.8 HIGH fbdev/ep93xx-fb: Do not assign to struct fb_info.dev
CVE-2023-53286 7.8 HIGH RDMA/mlx5: Return the firmware result upon destroying QP/RQ
CVE-2025-39818 7.8 HIGH HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save
CVE-2025-39825 7.8 HIGH smb: client: fix race with concurrent opens in rename(2)
CVE-2023-53274 7.8 HIGH clk: mediatek: mt8183: Add back SSPM related clocks

Showing top 20 of 115 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53324

No comments yet


Leave a comment