CVE-2023-52584: Linux Kernel
Low severity, CVSS 3.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif driver data that contains the clocks is allocated along with spmi_controller. On device remove, spmi_controller will be freed first, and then devres , including the clocks, will be cleanup. This leads to UAF because putting the clocks will access the clocks in the pmif driver data, which is already freed along with spmi_controller. This can be reproduced by enabling DEBUG_TEST_DRIVER_REMOVE and building the kernel with KASAN. Fix the UAF issue by using unmanaged clk_bulk_get() and putting the clocks before freeing spmi_controller.
Affected products
- Linux Linux Kernel: before 6.1.77 (fixed in 6.1.77); from 6.2, before 6.6.16 (fixed in 6.6.16); from 6.7, before 6.7.4 (fixed in 6.7.4)
Published 2024-03-06. Last modified 2026-06-17.