Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-54020

11
FAUCET Score

CVE-2023-54020 is a memory leak vulnerability in the Linux kernel's dmaengine sf-pdma driver. Specifically, a change intended to add multithread support inadvertently removed logic that recycled DMA descriptors, causing a new descriptor to be allocated without freeing the previous one each time sf_pdma_prep_dma_memcpy() is called. This leads to memory starvation over time. While no CVSS score is provided, the FAUCET Risk Score is 7/100, indicating a low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.10.137, < 5.11CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.61, < 5.15.99CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.18.18, < 5.19CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.19.2, < 5.20CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Advisories (1)

redhatCVE-2023-54020

kernel: dmaengine: sf-pdma: pdma_desc memory leak fix

Dec 24, 2025

References

git.kernel.org / stable/c/03fece43fa109beba7cc9948c02f5e2d1205d607
git.kernel.org / stable/c/8bd5040bd43f2b5ba3c898b09a3197a0c7ace126
git.kernel.org / stable/c/ad222c9af25e3f074c180e389b3477dce42afc4f
git.kernel.org / stable/c/b02e07015a5ac7bbc029da931ae17914b8ae0339