CVE-2023-54188
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2023-54188 is a memory leak vulnerability in the Linux kernel's dmaengine: apple-admac driver. The flaw exists in the terminate_all function, where the current_tx descriptor is not properly queued for freeing after being removed from the issued list, resulting in a kernel memory leak. It affects Linux kernel versions from commit b127315d9a78c011c011b88b92f650510edcfbd2 up to the patched commits in stable branches. The vulnerability was published on December 30, 2025, with an EPSS score of approximately 0.024% (very low), and no CVSS base score has been assigned (Red Hat Bugzilla, Feedly).

Technical details

The root cause is a missing resource cleanup (CWE-401: Missing Release of Memory after Effective Lifetime) in the Apple ADMAC DMA engine driver's terminate_all routine. When terminate_all is called, it correctly queues descriptors from the issued and submitted lists for freeing, but the current_tx descriptor — which is removed from the issued list when it becomes the active descriptor — is never explicitly queued for release. This results in a kernel memory leak each time terminate_all is invoked while a DMA transfer is in progress. The fix explicitly adds current_tx to the list of descriptors to be freed (Red Hat Bugzilla).

Impact

The primary impact of this vulnerability is a kernel memory leak on systems using the Apple ADMAC DMA engine driver, which is specific to Apple Silicon (ARM) hardware running Linux. Repeated triggering of the terminate_all path without proper cleanup can gradually exhaust kernel memory, potentially degrading system stability or availability over time. There is no known confidentiality or integrity impact, and the vulnerability does not enable code execution or privilege escalation (Red Hat Bugzilla).

Exploitability

This vulnerability has a very low EPSS score of approximately 0.024%, reflecting minimal exploitation likelihood. There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, no threat actor attribution, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is limited to systems running Linux on Apple Silicon hardware with the ADMAC DMA driver active (Feedly).

Mitigation and workarounds

Patches have been applied to multiple Linux stable branches. The fix is included in kernel versions at or after commits b7abd535881a48587961c2099b1d2933ebd42c4b (for one stable branch), fd4d88e68c75caf5c6f8293a36bc3ae289e0369e, and d9503be5a100c553731c0e8a82c7b4201e8a970c. Patched stable releases include Linux 6.1.25, 6.2.12, and 6.3. Users running Linux on Apple Silicon hardware should update to a patched kernel version. No configuration-based workaround is available beyond avoiding use of the affected DMA driver (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management