CVE-2023-54026

Linux Kernel 5.12-5.15.121, 5.16-6.1.40, 6.2-6.4.5 - Use-After-Free in OPP Table Lazy Linking

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: opp: Fix use-after-free in lazy_opp_tables after probe deferral When dev_pm_opp_of_find_icc_paths() in _allocate_opp_table() returns -EPROBE_DEFER, the opp_table is freed again, to wait until all the interconnect paths are available. However, if the OPP table is using required-opps then it may already have been added to the global lazy_opp_tables list. The error path does not remove the opp_table from the list again. This can cause crashes later when the provider of the required-opps is added, since we will iterate over OPP tables that have already been freed. E.g.: Unable to handle kernel NULL pointer dereference when read CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.4.0-rc3 PC is at _of_add_opp_table_v2 (include/linux/of.h:949 drivers/opp/of.c:98 drivers/opp/of.c:344 drivers/opp/of.c:404 drivers/opp/of.c:1032) -> lazy_link_required_opp_table() Fix this by calling _of_clear_opp_table() to remove the opp_table from the list and clear other allocated resources. While at it, also add the missing mutex_destroy() calls in the error path.

Scores

EPSS 0.0016
EPSS Percentile 5.9%

Details

Status published
Products (13)
linux/Kernel 5.12.0 - 5.15.121linux
linux/Kernel 5.16.0 - 6.1.40linux
linux/Kernel 6.2.0 - 6.4.5linux
Linux/Linux < 5.12
Linux/Linux 5.12
Linux/Linux 5.15.121 - 5.15.*
Linux/Linux 6.1.40 - 6.1.*
Linux/Linux 6.4.5 - 6.4.*
Linux/Linux 6.5
Linux/Linux 7eba0c7641b0009818e469dbfcdd87a0155ab9d4 - 39a0e723d3502f6dc4c603f57ebe8dc7bcc4a4bc
... and 3 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026