CVE-2023-54078
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54078 is a memory leak vulnerability in the Linux kernel's media: max9286 driver, where the V4L2 control handler is not properly freed in certain probe-time error paths and during device removal. The flaw affects Linux kernel versions starting from commit 66d8c9d2422da21ed41f75c03ba0685987b65fe0 (introduced in kernel 5.9) up to the patched stable releases. Fixed versions include Linux 5.10.180, 5.15.111, 6.1.28, 6.2.15, 6.3.2, and 6.4. It was published on December 24, 2025, with an EPSS score of 0.024% (Low), and no CVSS base score has been assigned (Feedly, EUVD).

Technical details

The root cause is a resource management error (CWE-401: Missing Release of Memory after Effective Lifetime) in the max9286 GMSL deserializer driver within the Linux kernel's media subsystem. The V4L2 control handler allocated during driver probe is not released when subsequent initialization steps fail, nor when the driver is unloaded via the remove path. This results in a kernel memory leak each time the driver is probed unsuccessfully or removed. The fix involves adding the appropriate v4l2_ctrl_handler_free() calls in the relevant error and cleanup paths (Feedly, EUVD).

Impact

The primary impact is a kernel memory leak, which can gradually exhaust kernel memory resources over time, potentially leading to system instability or denial of service on affected systems. The vulnerability is limited to systems using the max9286 GMSL camera deserializer hardware (commonly found in automotive and embedded Linux platforms). There is no known path to privilege escalation, code execution, or data exfiltration from this vulnerability (Feedly).

Mitigation and workarounds

Apply the upstream Linux kernel patches that introduce the missing v4l2_ctrl_handler_free() calls in the max9286 driver. The following stable kernel versions contain the fix: 5.10.180, 5.15.111, 6.1.28, 6.2.15, 6.3.2, and 6.4. Distributions using affected kernel versions (5.9 through the above patch points) should update to a patched release. As a workaround on systems where the max9286 hardware is not present, the driver module can be blacklisted to prevent loading (EUVD, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management