CVE-2023-53759: Linux
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: HID: hidraw: fix data race on device refcount The hidraw_open() function increments the hidraw device reference counter. The counter has no dedicated synchronization mechanism, resulting in a potential data race when concurrently opening a device. The race is a regression introduced by commit 8590222e4b02 ("HID: hidraw: Replace hidraw device table mutex with a rwsem"). While minors_rwsem is intended to protect the hidraw_table itself, by instead acquiring the lock for writing, the reference counter is also protected. This is symmetrical to hidraw_release().
Affected products
- Linux Linux: from 5.17, before 6.1.37 (fixed in 6.1.37); from 6.2, before 6.3.11 (fixed in 6.3.11); from 6.4, before 6.4.1 (fixed in 6.4.1)
Published 2025-12-08. Last modified 2026-08-04.