CVE-2023-53636 PUBLISHED CVSS 7.800000190734863 HIGH

In the Linux kernel, the following vulnerability has been resolved: clk: microchip: fix potential UAF in auxdev release callback Similar to commit 1c11289b34ab ("peci: cpu: Fix use-after-free in adev_release()"), the auxiliary device is not torn down in the correct order. If auxiliary_device_add() fails, the release callback will be called twice, resulting in a UAF. Due to timing, the auxdev code in this driver "took inspiration" from the aforementioned commit, and thus its bugs too! Moving auxiliary_device_uninit() to the unregister callback instead avoids the issue.

EPSS 0.02% · 3.4th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.02%
3.4th percentile

Affected Products

VendorProductVersions
LinuxLinuxb56bae2dd6fda6baf3bb74af3812676eebdd52f2, b56bae2dd6fda6baf3bb74af3812676eebdd52f2, b56bae2dd6fda6baf3bb74af3812676eebdd52f2
linuxlinux_kernel6.1, 6.1, 6.1

Timeline

References

Open in Interactive Console →