{"id":"DEBIAN-CVE-2023-53637","details":"In the Linux kernel, the following vulnerability has been resolved:  media: i2c: ov772x: Fix memleak in ov772x_probe()  A memory leak was reported when testing ov772x with bpf mock device:  AssertionError: unreferenced object 0xffff888109afa7a8 (size 8):   comm \"python3\", pid 279, jiffies 4294805921 (age 20.681s)   hex dump (first 8 bytes):     80 22 88 15 81 88 ff ff                          .\"......   backtrace:     [\u003c000000009990b438\u003e] __kmalloc_node+0x44/0x1b0     [\u003c000000009e32f7d7\u003e] kvmalloc_node+0x34/0x180     [\u003c00000000faf48134\u003e] v4l2_ctrl_handler_init_class+0x11d/0x180 [videodev]     [\u003c00000000da376937\u003e] ov772x_probe+0x1c3/0x68c [ov772x]     [\u003c000000003f0d225e\u003e] i2c_device_probe+0x28d/0x680     [\u003c00000000e0b6db89\u003e] really_probe+0x17c/0x3f0     [\u003c000000001b19fcee\u003e] __driver_probe_device+0xe3/0x170     [\u003c0000000048370519\u003e] driver_probe_device+0x49/0x120     [\u003c000000005ead07a0\u003e] __device_attach_driver+0xf7/0x150     [\u003c0000000043f452b8\u003e] bus_for_each_drv+0x114/0x180     [\u003c00000000358e5596\u003e] __device_attach+0x1e5/0x2d0     [\u003c0000000043f83c5d\u003e] bus_probe_device+0x126/0x140     [\u003c00000000ee0f3046\u003e] device_add+0x810/0x1130     [\u003c00000000e0278184\u003e] i2c_new_client_device+0x359/0x4f0     [\u003c0000000070baf34f\u003e] of_i2c_register_device+0xf1/0x110     [\u003c00000000a9f2159d\u003e] of_i2c_notify+0x100/0x160 unreferenced object 0xffff888119825c00 (size 256):   comm \"python3\", pid 279, jiffies 4294805921 (age 20.681s)   hex dump (first 32 bytes):     00 b4 a5 17 81 88 ff ff 00 5e 82 19 81 88 ff ff  .........^......     10 5c 82 19 81 88 ff ff 10 5c 82 19 81 88 ff ff  .\\.......\\......   backtrace:     [\u003c000000009990b438\u003e] __kmalloc_node+0x44/0x1b0     [\u003c000000009e32f7d7\u003e] kvmalloc_node+0x34/0x180     [\u003c0000000073d88e0b\u003e] v4l2_ctrl_new.cold+0x19b/0x86f [videodev]     [\u003c00000000b1f576fb\u003e] v4l2_ctrl_new_std+0x16f/0x210 [videodev]     [\u003c00000000caf7ac99\u003e] ov772x_probe+0x1fa/0x68c [ov772x]     [\u003c000000003f0d225e\u003e] i2c_device_probe+0x28d/0x680     [\u003c00000000e0b6db89\u003e] really_probe+0x17c/0x3f0     [\u003c000000001b19fcee\u003e] __driver_probe_device+0xe3/0x170     [\u003c0000000048370519\u003e] driver_probe_device+0x49/0x120     [\u003c000000005ead07a0\u003e] __device_attach_driver+0xf7/0x150     [\u003c0000000043f452b8\u003e] bus_for_each_drv+0x114/0x180     [\u003c00000000358e5596\u003e] __device_attach+0x1e5/0x2d0     [\u003c0000000043f83c5d\u003e] bus_probe_device+0x126/0x140     [\u003c00000000ee0f3046\u003e] device_add+0x810/0x1130     [\u003c00000000e0278184\u003e] i2c_new_client_device+0x359/0x4f0     [\u003c0000000070baf34f\u003e] of_i2c_register_device+0xf1/0x110  The reason is that if priv-\u003ehdl.error is set, ov772x_probe() jumps to the error_mutex_destroy without doing v4l2_ctrl_handler_free(), and all resources allocated in v4l2_ctrl_handler_init() and v4l2_ctrl_new_std() are leaked.","modified":"2026-09-15T09:02:46.673145842Z","published":"2025-10-07T16:15:46.883Z","upstream":["CVE-2023-53637"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53637"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53637.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53637.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53637.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}