CVE-2023-53637
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53637 is a memory leak vulnerability discovered in the Linux kernel's media subsystem, specifically in the ov772x driver's probe function. The vulnerability was disclosed and documented in October 2025 (NVD).

Technical details

The vulnerability occurs in the ov772x_probe() function where if priv->hdl.error is set, the function jumps to error_mutex_destroy without properly freeing resources allocated by v4l2_ctrl_handler_init() and v4l2_ctrl_new_std(). This results in memory leaks of two objects: one of size 8 bytes and another of size 256 bytes (NVD).

Impact

The vulnerability leads to memory leaks in the Linux kernel when testing the ov772x driver with bpf mock device, potentially causing system resource depletion over time (NVD).

Mitigation and workarounds

The issue has been resolved through a patch that properly handles resource cleanup in the error path of the ov772x_probe() function (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-nvidia-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • linux-oracle-6.14
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-devel
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management