CVE-2023-53459

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
01/10/2025
Last modified:
16/01/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> HID: mcp-2221: prevent UAF in delayed work<br /> <br /> If the device is plugged/unplugged without giving time for mcp_init_work()<br /> to complete, we might kick in the devm free code path and thus have<br /> unavailable struct mcp_2221 while in delayed work.<br /> <br /> Canceling the delayed_work item is enough to solve the issue, because<br /> cancel_delayed_work_sync will prevent the work item to requeue itself.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:6.2:*:*:*:*:*:*:*