CVE-2023-53106: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition This bug influences both st_nci_i2c_remove and st_nci_spi_remove. Take st_nci_i2c_remove as an example. In st_nci_i2c_probe, it called ndlc_probe and bound &ndlc->sm_work with llt_ndlc_sm_work. When it calls ndlc_recv or timeout handler, it will finally call schedule_work to start the work. When we call st_nci_i2c_remove to remove the driver, there may be a sequence as follows: Fix it by finishing the work before cleanup in ndlc_remove CPU0 CPU1 |llt_ndlc_sm_work st_nci_i2c_remove | ndlc_remove | st_nci_remove | nci_free_device| kfree(ndev) | //free ndlc->ndev | |llt_ndlc_rcv_queue |nci_recv_frame |//use ndlc->ndev
Affected products
- Linux Linux Kernel: from 3.17, before 4.14.311 (fixed in 4.14.311); from 4.15, before 4.19.279 (fixed in 4.19.279); from 4.20, before 5.4.238 (fixed in 5.4.238); from 5.5, before 5.10.176 (fixed in 5.10.176); from 5.11, before 5.15.104 (fixed in 5.15.104); from 5.16, before 6.1.21 (fixed in 6.1.21); …
Published 2025-05-02. Last modified 2026-06-17.