CVE-2023-53274
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/09/2025
Last modified:
16/09/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
clk: mediatek: mt8183: Add back SSPM related clocks<br />
<br />
This reverts commit 860690a93ef23b567f781c1b631623e27190f101.<br />
<br />
On the MT8183, the SSPM related clocks were removed claiming a lack of<br />
usage. This however causes some issues when the driver was converted to<br />
the new simple-probe mechanism. This mechanism allocates enough space<br />
for all the clocks defined in the clock driver, not the highest index<br />
in the DT binding. This leads to out-of-bound writes if their are holes<br />
in the DT binding or the driver (due to deprecated or unimplemented<br />
clocks). These errors can go unnoticed and cause memory corruption,<br />
leading to crashes in unrelated areas, or nothing at all. KASAN will<br />
detect them.<br />
<br />
Add the SSPM related clocks back to the MT8183 clock driver to fully<br />
implement the DT binding. The SSPM clocks are for the power management<br />
co-processor, and should never be turned off. They are marked as such.



