CVE-2023-53472: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: pwm: lpc32xx: Remove handling of PWM channels Because LPC32xx PWM controllers have only a single output which is registered as the only PWM device/channel per controller, it is known in advance that pwm->hwpwm value is always 0. On basis of this fact simplify the code by removing operations with pwm->hwpwm, there is no controls which require channel number as input. Even though I wasn't aware at the time when I forward ported that patch, this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL before devm_pwmchip_add() is called.
Affected products
- Linux Linux Kernel: from 4.9.284, before 4.10 (fixed in 4.10); from 4.14.248, before 4.14.326 (fixed in 4.14.326); from 4.19.208, before 4.19.295 (fixed in 4.19.295); from 5.4.149, before 5.4.257 (fixed in 5.4.257); from 5.10.69, before 5.10.195 (fixed in 5.10.195); from 5.14.8, before 5.15.132 (fixed in 5.15.132); …
Published 2025-10-01. Last modified 2026-06-17.