CVE-2023-52584
spmi: mediatek: Fix UAF on device remove
Record summary
CVE-2023-52584 has a selected CVSS score of 3.8 (low).
Description
In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif driver data that contains the clocks is allocated along with spmi_controller. On device remove, spmi_controller will be freed first, and then devres , including the clocks, will be cleanup. This leads to UAF because putting the clocks will access the clocks in the pmif driver data, which is already freed along with spmi_controller. This can be reproduced by enabling DEBUG_TEST_DRIVER_REMOVE and building the kernel with KASAN. Fix the UAF issue by using unmanaged clk_bulk_get() and putting the clocks before freeing spmi_controller.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
LinuxBrowse Linux / LinuxDefault status: unaffected, affected | CVE List | b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < 521f28eedd6b14228c46e3b81e3bf9b90c2818d8 | affected |
| b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < f8dcafcb54632536684336161da8bdd52120f95e | affected | ||
| b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < 9a3881b1f07db1bb55cb0108e6f05cfd027eaf2e | affected | ||
| b45b3ccef8c063d21eb746d85337eaf71f6b5f07 to < e821d50ab5b956ed0effa49faaf29912fd4106d9 | affected | ||
| 5.17 | affected | ||
| Before 5.17 | unaffected | ||
| 6.1.77 to ≤ 6.1.* | unaffected | ||
| 6.6.16 to ≤ 6.6.* | unaffected | ||
| 6.7.4 to ≤ 6.7.* | unaffected | ||
| 6.8 to ≤ * | unaffected | ||
kernelBrowse linux / kernelDefault status: unknown | CVE List | 1da177e4c3f4 to < 521f28eedd6b | affected |
| 1da177e4c3f4 to < f8dcafcb5463 | affected | ||
| 1da177e4c3f4 to < 9a3881b1f07d | affected | ||
| 1da177e4c3f4 to < e821d50ab5b9 | affected | ||
| 6.1.77 to ≤ 6.1.* | unaffected | ||
| 6.6.16 to ≤ 6.6.* | unaffected | ||
| 6.7.4 to ≤ 6.7.* | unaffected | ||
| 6.8 to ≤ * | unaffected | ||
KernelBrowse Linux / Kernel | OSV | 5.17.0 to < 6.1.77 · Fixed in 6.1.77 | affected |
| 6.2.0 to < 6.6.16 · Fixed in 6.6.16 | affected | ||
| 6.7.0 to < 6.7.4 · Fixed in 6.7.4 | affected |