CVE-2023-53012

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/03/2025
Last modified:
30/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> thermal: core: call put_device() only after device_register() fails<br /> <br /> put_device() shouldn&amp;#39;t be called before a prior call to<br /> device_register(). __thermal_cooling_device_register() doesn&amp;#39;t follow<br /> that properly and needs fixing. Also<br /> thermal_cooling_device_destroy_sysfs() is getting called unnecessarily<br /> on few error paths.<br /> <br /> Fix all this by placing the calls at the right place.<br /> <br /> Based on initial work done by Caleb Connolly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.86 (including) 5.16 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.0.16 (including) 6.1 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.2 (including) 6.2 (excluding)
cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:*