Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: nvidia-shield: Reference hid_device devm allocation of input_dev name Use hid_device for devm allocation of the input_dev name to avoid a use-after-free. input_unregister_device would trigger devres cleanup of all resources associated with the input_dev, free-ing the name. The name would subsequently be used in a uevent fired at the end of unregistering the input_dev.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.5, < 6.5.3 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/197d3143520fec9fde89aebabc9f0d7464f08e50Patch
- https://git.kernel.org/stable/c/b85d3807e5ec368bfd5b20245347d7c1434aff76Patch
FAQ
What is CVE-2023-53253?
CVE-2023-53253 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: HID: nvidia-shield: Reference hid_device devm allocation of input_dev name Use hid_device for devm allocation of the input_dev nam...
How severe is CVE-2023-53253?
CVE-2023-53253 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53253?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.