CVE-2023-54097 is a memory leak vulnerability in the Linux kernel's stm32-pwr regulator driver. Specifically, the 'base' memory allocated by of_iomap() is not properly released if subsequent memory allocation or device registration fails during the stm32_pwr_regulator_probe() function. This issue affects systems utilizing the stm32-pwr regulator. The vulnerability's severity is considered low, with no CVSS score provided and a FAUCET Risk Score of 7/100. It is a local memory leak, meaning it would likely require local access to exploit and does not present a direct attack vector for remote compromise. The potential impact is resource exhaustion rather than direct data compromise or system control. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed on CISA's KEV catalog or any hot lists, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.2CNA affecteddefault affected | |
| Linux | Linux | >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < 0ad07e02be0d3f0d554653382ffe53ae4879378d, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < 824683dbec234a01bd49a0589ee3323594a6f4cf, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < ad6481f49fb2c703efa3a929643934f24b666d6a, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < c091bb49b3233307c7af73dae888f0799752af3d, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < c4a413e56d16a2ae84e6d8992f215c4dcc7fac20, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < dfce9bb3517a78507cf96f9b83948d0b81338afa, >= dc62f951a6a8490bcccc7b6de36cd85bd57be740, < f25994f7a9ad53eb756bc4869497c3ebe281ad5eCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.