CVE-2023-54255
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54255 is a kernel panic vulnerability in the Linux kernel's SuperH (SH) DMA subsystem caused by incorrect DMA channel offset calculations. It affects SoCs of the SH3, SH4, and SH4A family that use the sh/dma driver, where differing numbers of DMA channels distributed across up to two DMAC modules are not correctly handled. The vulnerability was published on December 30, 2025, and has a CVSS base score of 0.0 as assessed by ENISA (no severity rating assigned), with an EPSS score of 0.00032 (Feedly, ENISA EUVD).

Technical details

The root cause is an improper calculation in dma_base_addr(), which fails to correctly compute channel offsets when DMA channels are distributed between two DMAC modules on SH3/SH4/SH4A SoCs (CWE-682: Incorrect Calculation). Additionally, dmaor_read_reg() and dmaor_write_reg() incorrectly select the DMAC module base for the DMAOR register, compounding the miscalculation. The fix rewrites dma_base_addr() and corrects the DMAC module base selection logic in the register access functions. The vulnerability is local in nature, requiring the affected hardware platform to trigger the faulty code path, which results in a kernel panic (Feedly).

Impact

Exploitation of this vulnerability leads to a kernel panic (system crash), resulting in a complete loss of availability for systems running affected SH3/SH4/SH4A-based hardware. There is no known confidentiality or integrity impact, and the scope is limited to the local system. Lateral movement or data exfiltration are not associated with this vulnerability given its nature as a crash-inducing calculation error (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have released patches across multiple stable branches. Fixed versions include kernel 4.14.322, 4.19.291, 5.4.251, 5.10.188, 5.15.121, 6.1.39, 6.4.4, and 6.5. Users running SH3/SH4/SH4A-based systems should update to a patched kernel version. The relevant upstream commits are available in the Linux stable kernel repository (Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management