CVE-2023-53801
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53801 is a memory leak vulnerability in the Linux kernel's IOMMU driver for Spreadtrum (SPRD) platforms. The flaw occurs in the iommu/sprd subsystem, where a DMA buffer allocated during domain attachment to store the address mapping table is not released when the IOMMU domain is freed. It affects Linux kernel versions from the initial commit (1da177e4c3f4) up to the fixes introduced in stable releases 5.15.113, 6.1.81, 6.3.4, and 6.4. The vulnerability was published on December 9, 2025, and carries an estimated CVSS severity of Medium with an EPSS score of approximately 0.018% (Feedly, ENISA EUVD).

Technical details

The root cause is a missing deallocation of a DMA buffer in the iommu/sprd driver (CWE-401: Missing Release of Memory after Effective Lifetime). When a device attaches to an IOMMU domain, the driver allocates a DMA buffer to hold the address mapping table; however, the corresponding free operation is absent from the domain teardown path, causing the memory to leak each time a domain is destroyed. Exploitation requires local access to a system running an affected kernel version on Spreadtrum-based hardware. No public proof-of-concept exploit code has been identified for this vulnerability (Feedly, ENISA EUVD).

Impact

The primary impact is an availability concern: repeated allocation and non-release of DMA buffers can exhaust kernel memory over time, potentially leading to system instability or denial of service on affected Spreadtrum-based devices. There is no evidence of confidentiality or integrity impact, and the vulnerability does not enable privilege escalation or remote code execution. The scope is limited to systems using the iommu/sprd driver, which is specific to Spreadtrum SoC platforms (Feedly).

Exploitability

There is no known active exploitation of CVE-2023-53801 in the wild, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.018%, reflecting minimal exploitation probability. No exploit kits, weaponized code, or threat actor attribution have been associated with this vulnerability (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released fixes in stable versions 5.15.113, 6.1.81, 6.3.4, and 6.4, which add the missing DMA buffer release in the IOMMU domain free path. Administrators running affected kernels on Spreadtrum-based hardware should upgrade to one of these patched stable releases. The relevant upstream commits are 9afea57384d4, 92c089a931fd, 8745f3592ee4, and d0a917fd5e3b (ENISA EUVD, Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management