CVE-2023-53274
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
16/09/2025
Last modified:
14/01/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
clk: mediatek: mt8183: Add back SSPM related clocks<br />
<br />
This reverts commit 860690a93ef23b567f781c1b631623e27190f101.<br />
<br />
On the MT8183, the SSPM related clocks were removed claiming a lack of<br />
usage. This however causes some issues when the driver was converted to<br />
the new simple-probe mechanism. This mechanism allocates enough space<br />
for all the clocks defined in the clock driver, not the highest index<br />
in the DT binding. This leads to out-of-bound writes if their are holes<br />
in the DT binding or the driver (due to deprecated or unimplemented<br />
clocks). These errors can go unnoticed and cause memory corruption,<br />
leading to crashes in unrelated areas, or nothing at all. KASAN will<br />
detect them.<br />
<br />
Add the SSPM related clocks back to the MT8183 clock driver to fully<br />
implement the DT binding. The SSPM clocks are for the power management<br />
co-processor, and should never be turned off. They are marked as such.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.4 (including) | 6.4.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.5:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.5:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.5:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.5:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



