CVE-2023-53385: media: mdp3: Fix resource leaks in of_find_device_by_node
In the Linux kernel, the following vulnerability has been resolved:
media: mdp3: Fix resource leaks in of_find_device_by_node
Use put_device to release the object get through of_find_device_by_node,
avoiding resource leaks.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel resource-leak flaw in the media mdp3 code. A local authenticated user could potentially consume kernel resources and cause availability impact. The public record does not show remote exploitation or active exploitation.
Executive priority
Treat this as a moderate availability risk. It is not currently supported as a remote or actively exploited issue, but it matters for shared Linux systems where local users could trigger resource exhaustion.
Technical view
The flaw is a CWE-401 resource leak: mdp3 code obtains a device object through of_find_device_by_node but did not release it with put_device. CVSS is 5.5: local attack vector, low complexity, low privileges, no user interaction, and availability-only impact.
Likely exposure
Exposure is most likely on systems running affected Linux kernel versions or downstream packages that include the vulnerable mdp3 media driver code. The source data lists Linux kernel 6.1, 6.1.55, 6.5.5, and 6.6 among affected entries, but downstream vendor status requires confirmation.
Exploitation context
No KEV listing is provided, and the source bundle contains no evidence of active exploitation. The CVSS vector indicates exploitation requires local privileges and targets availability, not confidentiality or integrity.
Researcher notes
The public description is narrow and patch-oriented. It identifies a missing put_device after of_find_device_by_node in media mdp3. Affected-version metadata appears limited and partly ambiguous, so validate against kernel commit history and downstream vendor backports.
Mitigation direction
Update to a kernel or vendor package that includes the referenced stable fixes.
Check Linux distribution advisories for exact patched package versions.
Prioritize shared systems with untrusted local users or container workloads.
Do not assume network-facing exposure without product-specific evidence.
Track vendor guidance if running custom or embedded kernels.
Validation and detection
Inventory running kernel versions across Linux hosts and appliances.
Confirm whether affected builds include the mdp3 media driver code.
Compare vendor package status against the referenced stable commits.
Verify remediation by confirming the running kernel includes the fix.
Document exceptions where vendor guidance is unavailable or incomplete.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-401: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-401 · source CWE mapping
Missing Release of Memory after Effective Lifetime
Missing Release of Memory after Effective Lifetime represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.