Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53801— iommu/sprd: Release dma buffer to avoid memory leak

AI Predicted 5.5 Difficulty: Easy EPSS 0.18% · P8

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinuxb23e4fc4e3faed0b8b604079c44a244da3ec941a< 92c089a931fd3939cd32318cf4f54e69e8f51a19affected
b23e4fc4e3faed0b8b604079c44a244da3ec941a< 8745f3592ee4a7b49ede16ddd3f12a41ecaa23c9affected
b23e4fc4e3faed0b8b604079c44a244da3ec941a< d0a917fd5e3b3ed9d9306b4260ba684b982da9f3affected
b23e4fc4e3faed0b8b604079c44a244da3ec941a< 9afea57384d4ae7b2034593eac7fa76c7122762aaffected
5.13affected
< 5.13unaffected
5.15.113≤ 5.15.*unaffected
6.1.81≤ 6.1.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53801

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
iommu/sprd: Release dma buffer to avoid memory leak
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iommu/sprd: Release dma buffer to avoid memory leak When attaching to a domain, the driver would alloc a DMA buffer which is used to store address mapping table, and it need to be released when the IOMMU domain is freed.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sprd iommu驱动未释放DMA缓冲区,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux b23e4fc4e3faed0b8b604079c44a244da3ec941a ~ 92c089a931fd3939cd32318cf4f54e69e8f51a19 -
LinuxLinux 5.13 -

II. Public POCs for CVE-2023-53801

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53801

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-09 · 152 CVEs total

CVE-2022-506669.8 CRITICALRDMA/siw: Fix QP destroy to wait for all references dropped.
CVE-2025-403439.8 CRITICALnvmet-fc: avoid scheduling association deletion twice
CVE-2023-537949.8 CRITICALcifs: fix session state check in reconnect to avoid use-after-free issue
CVE-2025-403428.8 HIGHnvme-fc: use lock accessing port_state and rport state
CVE-2023-538228.8 HIGHwifi: ath11k: Ignore frags from uninitialized peer in dp.
CVE-2023-537858.8 HIGHmt76: mt7921: don't assume adequate headroom for SDIO headers
CVE-2025-403368.8 HIGHdrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2023-538278.8 HIGHBluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
CVE-2025-403288.8 HIGHsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2023-538518.4 HIGHdrm/msm/dp: Drop aux devices together with DP controller
CVE-2025-403378.2 HIGHnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2022-506568.1 HIGHnfc: pn533: Clear nfc_target before being used
CVE-2023-538038.1 HIGHscsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
CVE-2023-538007.8 HIGHubi: Fix use-after-free when volume resizing failed
CVE-2023-538607.8 HIGHdm: don't attempt to queue IO under RCU protection
CVE-2023-538297.8 HIGHf2fs: flush inode if atomic file is aborted
CVE-2023-537907.8 HIGHbpf: Zeroing allocated object from slab in bpf memory allocator
CVE-2023-538367.8 HIGHbpf, sockmap: Fix skb refcnt race after locking changes
CVE-2023-538447.8 HIGHdrm/ttm: Don't leak a resource on swapout move error
CVE-2023-538467.8 HIGHf2fs: fix to do sanity check on direct node in truncate_dnode()

Showing top 20 of 152 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53801

No comments yet


Leave a comment