CVE-2023-54207
HIGHLinux Kernel - Use After Free
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.
References (6)
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
6.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
published
Affected Products (4)
linux/Kernel
< 6.1.53linux
linux/Kernel
< 6.4.16linux
linux/Kernel
< 6.5.3linux
linux/linux_kernel
< 5.10.249
Timeline
Published
Dec 30, 2025
Tracked Since
Feb 18, 2026