« Volver al listado

CVE-2023-53854

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ASoC: mediatek: mt8186: Fix use-after-free in driver remove path

When devm runs function in the "remove" path for a device it runs them in the reverse order. That means that if you have parts of your driver that aren't using devm or are using "roll your own" devm w/ devm_add_action_or_reset() you need to keep that in mind.

The mt8186 audio driver didn't quite get this right. Specifically, in mt8186_init_clock() it called mt8186_audsys_clk_register() and then went on to call a bunch of other devm function. The caller of mt8186_init_clock() used devm_add_action_or_reset() to call mt8186_deinit_clock() but, because of the intervening devm functions, the order was wrong.

Leer descripción completaMostrar menos

Specifically at probe time, the order was: 1. mt8186_audsys_clk_register() 2. afe_priv->clk = devm_kcalloc(...) 3. afe_priv->clk[i] = devm_clk_get(...)

At remove time, the order (which should have been 3, 2, 1) was: 1. mt8186_audsys_clk_unregister() 3. Free all of afe_priv->clk[i] 2. Free afe_priv->clk

The above seemed to be causing a use-after-free. Luckily, it's easy to fix this by simply using devm more correctly. Let's move the devm_add_action_or_reset() to the right place. In addition to fixing the use-after-free, code inspection shows that this fixes a leak (missing call to mt8186_audsys_clk_unregister()) that would have happened if any of the syscon_regmap_lookup_by_phandle() calls in mt8186_init_clock() had failed.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53854",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "55b423d5623ccd6785429431c2cf5f3e073b73ba",
              "lessThan": "3e56a1c04882852e3e7d6c59756a16211ebbc457",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "55b423d5623ccd6785429431c2cf5f3e073b73ba",
              "lessThan": "dffd9e2b57cb845930fa885aa634a847ba2130dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "55b423d5623ccd6785429431c2cf5f3e073b73ba",
              "lessThan": "a93d2afd3f77a7331271a0f25c6a11003db69b3c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/soc/mediatek/mt8186/mt8186-afe-clk.c",
            "sound/soc/mediatek/mt8186/mt8186-afe-clk.h",
            "sound/soc/mediatek/mt8186/mt8186-afe-pcm.c",
            "sound/soc/mediatek/mt8186/mt8186-audsys-clk.c",
            "sound/soc/mediatek/mt8186/mt8186-audsys-clk.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.30",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.3.4",
              "versionType": "semver",
              "lessThanOrEqual": "6.3.*"
            },
            {
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/soc/mediatek/mt8186/mt8186-afe-clk.c",
            "sound/soc/mediatek/mt8186/mt8186-afe-clk.h",
            "sound/soc/mediatek/mt8186/mt8186-afe-pcm.c",
            "sound/soc/mediatek/mt8186/mt8186-audsys-clk.c",
            "sound/soc/mediatek/mt8186/mt8186-audsys-clk.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-09T16:17:26.060",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3e56a1c04882852e3e7d6c59756a16211ebbc457",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a93d2afd3f77a7331271a0f25c6a11003db69b3c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dffd9e2b57cb845930fa885aa634a847ba2130dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: mt8186: Fix use-after-free in driver remove path\n\nWhen devm runs function in the \"remove\" path for a device it runs them\nin the reverse order. That means that if you have parts of your driver\nthat aren't using devm or are using \"roll your own\" devm w/\ndevm_add_action_or_reset() you need to keep that in mind.\n\nThe mt8186 audio driver didn't quite get this right. Specifically, in\nmt8186_init_clock() it called mt8186_audsys_clk_register() and then\nwent on to call a bunch of other devm function. The caller of\nmt8186_init_clock() used devm_add_action_or_reset() to call\nmt8186_deinit_clock() but, because of the intervening devm functions,\nthe order was wrong.\n\nSpecifically at probe time, the order was:\n1. mt8186_audsys_clk_register()\n2. afe_priv->clk = devm_kcalloc(...)\n3. afe_priv->clk[i] = devm_clk_get(...)\n\nAt remove time, the order (which should have been 3, 2, 1) was:\n1. mt8186_audsys_clk_unregister()\n3. Free all of afe_priv->clk[i]\n2. Free afe_priv->clk\n\nThe above seemed to be causing a use-after-free. Luckily, it's easy to\nfix this by simply using devm more correctly. Let's move the\ndevm_add_action_or_reset() to the right place. In addition to fixing\nthe use-after-free, code inspection shows that this fixes a leak\n(missing call to mt8186_audsys_clk_unregister()) that would have\nhappened if any of the syscon_regmap_lookup_by_phandle() calls in\nmt8186_init_clock() had failed."
    }
  ],
  "lastModified": "2026-06-17T06:46:11.367",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}