CVE-2023-54020 is a memory leak vulnerability in the Linux kernel's dmaengine sf-pdma driver. Specifically, a change intended to add multithread support inadvertently removed logic that recycled DMA descriptors, causing a new descriptor to be allocated without freeing the previous one each time sf_pdma_prep_dma_memcpy() is called. This leads to memory starvation over time. While no CVSS score is provided, the FAUCET Risk Score is 7/100, indicating a low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.137, < 5.11CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.61, < 5.15.99CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.18.18, < 5.19CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.19.2, < 5.20CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.