Record summary

CVE-2023-52584 has a selected CVSS score of 3.8 (low).

Description

In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif driver data that contains the clocks is allocated along with spmi_controller. On device remove, spmi_controller will be freed first, and then devres , including the clocks, will be cleanup. This leads to UAF because putting the clocks will access the clocks in the pmif driver data, which is already freed along with spmi_controller. This can be reproduced by enabling DEBUG_TEST_DRIVER_REMOVE and building the kernel with KASAN. Fix the UAF issue by using unmanaged clk_bulk_get() and putting the clocks before freeing spmi_controller.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected, affected

CVE Listb45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < 521f28eedd6b14228c46e3b81e3bf9b90c2818d8affected
b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < f8dcafcb54632536684336161da8bdd52120f95eaffected
b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < 9a3881b1f07db1bb55cb0108e6f05cfd027eaf2eaffected
b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < e821d50ab5b956ed0effa49faaf29912fd4106d9affected
5.17affected
Before 5.17unaffected
6.1.77 to ≤ 6.1.*unaffected
6.6.16 to ≤ 6.6.*unaffected
6.7.4 to ≤ 6.7.*unaffected
6.8 to ≤ *unaffected

Default status: unknown

CVE List1da177e4c3f4 to < 521f28eedd6baffected
1da177e4c3f4 to < f8dcafcb5463affected
1da177e4c3f4 to < 9a3881b1f07daffected
1da177e4c3f4 to < e821d50ab5b9affected
6.1.77 to ≤ 6.1.*unaffected
6.6.16 to ≤ 6.6.*unaffected
6.7.4 to ≤ 6.7.*unaffected
6.8 to ≤ *unaffected
OSV5.17.0 to < 6.1.77 · Fixed in 6.1.77affected
6.2.0 to < 6.6.16 · Fixed in 6.6.16affected
6.7.0 to < 6.7.4 · Fixed in 6.7.4affected

References

7