CVE-2023-53454
HIGH EPSS 4.8%
Published Oct 1, 20259mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
Published Oct 1, 2025 9mo ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
4.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-416 Use After Free Memory Safety
Affected Products 8
References 9
- git.kernel.org https://git.kernel.org/stable/c/15ec7cb55e7d88755aa01d44a7a1015a42bfce86
- git.kernel.org https://git.kernel.org/stable/c/1d7833db9fd118415dace2ca157bfa603dec9c8c
- git.kernel.org https://git.kernel.org/stable/c/2763732ec1e68910719c75b6b896e11b6d3d622b
- git.kernel.org https://git.kernel.org/stable/c/39c70c19456e50dcb3abfe53539220dff0490f1d
- git.kernel.org https://git.kernel.org/stable/c/4794394635293a3e74591351fff469cea7ad15a2
- git.kernel.org https://git.kernel.org/stable/c/ac0d389402a6ff9ad92cea02c2d8c711483b91ab
- git.kernel.org https://git.kernel.org/stable/c/b70ac7849248ec8128fa12f86e3655ba38838f29
- git.kernel.org https://git.kernel.org/stable/c/dde88ab4e45beb60b217026207aa9c14c88d71ab
- git.kernel.org https://git.kernel.org/stable/c/df7ca43fe090e1a56c216c8ebc106ef5fd49afc6
Remediation
- git.kernel.org https://git.kernel.org/stable/c/15ec7cb55e7d88755aa01d44a7a1015a42bfce86
- git.kernel.org https://git.kernel.org/stable/c/1d7833db9fd118415dace2ca157bfa603dec9c8c
- git.kernel.org https://git.kernel.org/stable/c/2763732ec1e68910719c75b6b896e11b6d3d622b
- git.kernel.org https://git.kernel.org/stable/c/39c70c19456e50dcb3abfe53539220dff0490f1d
- git.kernel.org https://git.kernel.org/stable/c/4794394635293a3e74591351fff469cea7ad15a2
- git.kernel.org https://git.kernel.org/stable/c/ac0d389402a6ff9ad92cea02c2d8c711483b91ab
- git.kernel.org https://git.kernel.org/stable/c/b70ac7849248ec8128fa12f86e3655ba38838f29
- git.kernel.org https://git.kernel.org/stable/c/dde88ab4e45beb60b217026207aa9c14c88d71ab
- git.kernel.org https://git.kernel.org/stable/c/df7ca43fe090e1a56c216c8ebc106ef5fd49afc6