CVE-2023-53225

Availability loss via unreleased DMA resources

Published Sep 15, 2025 · Updated May 23, 2026

Resource leak in the Linux kernel i.MX SPI driver allows local users to impair availability via a failed device-removal path. The spi_imx_remove callback returns when pm_runtime_get_sync fails, bypassing DMA teardown and permanently retaining those resources. Reachability requires local access to an i.MX system using the driver and a device-wake failure during removal; repeated leaks can exhaust DMA resources.

CVSS severity5.5
Medium
EPSS probability0.16%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Resource leak in the Linux kernel i.MX SPI driver allows local users to impair availability via a failed device-removal path. The spi_imx_remove callback returns when pm_runtime_get_sync fails, bypassing DMA teardown and permanently retaining those resources. Reachability requires local access to an i.MX system using the driver and a device-wake failure during removal; repeated leaks can exhaust DMA resources.

The record

CVE
CVE-2023-53225
Published
Sep 15, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-401
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Sep 15, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=1333c3e996eb799286ee2ef2c01752da45bf926f
  2. Affected versionversion=28ae79a518421348abfc2a2dffd6a6b6e3699476
  3. Affected versionversion=3.16.57 <3.17
  4. Affected versionversion=3.18.94 <3.19
  5. Affected versionversion=4.14.17 <4.15
  6. Affected versionversion=4.1.50 <4.2
  7. Affected versionversion=4.15.1 <4.16
  8. Affected versionversion=4.16
  9. Affected versionversion=4.4.115 <4.5
  10. Affected versionversion=4.9.80 <4.10
  11. Affected versionversion=b6aaaaed67b170a9841f0f598cd45ccbfe76e15e
  12. Affected versionversion=bac4bf53ca7c65d6c06808aab70c6caa0b9c78b9
  13. Affected versionversion=cfd96cbd607ab5d63a33cd63673221f4d572ea8c
  14. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <11951c9e3f364d7ae3b568a0e52c8335d43066b5
  15. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <57a463226638f1ceabbb029cbd21b0c94640f1b5
  16. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <6d16305a1535873e0a8a8ae92ea2d9106ec2d7df
  17. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <aa93a46f998a9069368026ac52bba96868c59157
  18. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <b64cb3f085fed296103c91f0db6acad30a021b36
  19. Affected versionversion=d593574aff0ab846136190b1729c151c736727ec <f90822ad63d11301e425311dac0c8e12ca1737b8
  20. Affected versionversion=f84a8d446a16379df5844bc2bd50f0b7431a4718
  21. Affected versionversion=fc58a98f1c98b22d31c53913cca38d5c43807cb4

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=1333c3e996eb799286ee2ef2c01752da45bf926f; version=28ae79a518421348abfc2a2dffd6a6b6e3699476; version=3.16.57 <3.17; version=3.18.94 <3.19; version=4.14.17 <4.15; version=4.1.50 <4.2; version=4.15.1 <4.16; version=4.16; version=4.4.115 <4.5; version=4.9.80 <4.10; version=b6aaaaed67b170a9841f0f598cd45ccbfe76e15e; version=bac4bf53ca7c65d6c06808aab70c6caa0b9c78b9; version=cfd96cbd607ab5d63a33cd63673221f4d572ea8c; version=d593574aff0ab846136190b1729c151c736727ec <11951c9e3f364d7ae3b568a0e52c8335d43066b5; version=d593574aff0ab846136190b1729c151c736727ec <57a463226638f1ceabbb029cbd21b0c94640f1b5; version=d593574aff0ab846136190b1729c151c736727ec <6d16305a1535873e0a8a8ae92ea2d9106ec2d7df; version=d593574aff0ab846136190b1729c151c736727ec <aa93a46f998a9069368026ac52bba96868c59157; version=d593574aff0ab846136190b1729c151c736727ec <b64cb3f085fed296103c91f0db6acad30a021b36; version=d593574aff0ab846136190b1729c151c736727ec <f90822ad63d11301e425311dac0c8e12ca1737b8; version=f84a8d446a16379df5844bc2bd50f0b7431a4718; version=fc58a98f1c98b22d31c53913cca38d5c43807cb4

Published CVSS scores

5.5CISA ADP VulnrichmentCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-401Missing Release of Memory after Effective Lifetime

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo