Input: synaptics-rmi4 - fix use after free in rmi_unregister_function()
Published May 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
The put_device() calls rmi_release_function() which frees "fn" so the dereference on the next line "fn->num_of_irqs" is a use after free. Move the put_device() to the end to fix this.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.18StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.18
- Version 4.19.299StatusunaffectedConstraints<=4.19.*
- Version 5.10.201StatusunaffectedConstraints<=5.10.*
- Version 5.15.139StatusunaffectedConstraints<=5.15.*
- Version 5.4.261StatusunaffectedConstraints<=5.4.*
- Version 6.1.63StatusunaffectedConstraints<=6.1.*
- Version 6.5.12StatusunaffectedConstraints<=6.5.*
- Version 6.6.2StatusunaffectedConstraints<=6.6.*
- Version 6.7StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.18 · < 4.19.299
- ≥ 4.20 · < 5.4.261
- ≥ 5.5 · < 5.10.201
- ≥ 5.11 · < 5.15.139
- ≥ 5.16 · < 6.1.63
- ≥ 6.2 · < 6.5.12
- ≥ 6.6 · < 6.6.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.70.1.el9_4
Fixed · RHSA-2025:8248
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.70.1.el9_4 | Fixed | RHSA-2025:8248 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-52840 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282757 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59553 Advisory
- https://git.kernel.org/stable/c/2f236d8638f5b43e0c72919a6a27fe286c32053f Patch
- https://git.kernel.org/stable/c/303766bb92c5c225cf40f9bbbe7e29749406e2f2 Patch
- https://git.kernel.org/stable/c/50d12253666195a14c6cd2b81c376e2dbeedbdff Patch
- https://git.kernel.org/stable/c/6c71e065befb2fae8f1461559b940c04e1071bd5 Patch
- https://git.kernel.org/stable/c/7082b1fb5321037bc11ba1cf2d7ed23c6b2b521f Patch
- https://git.kernel.org/stable/c/c8e639f5743cf4b01f8c65e0df075fe4d782b585 Patch
- https://git.kernel.org/stable/c/cc56c4d17721dcb10ad4e9c9266e449be1462683 Patch
- https://git.kernel.org/stable/c/eb988e46da2e4eae89f5337e047ce372fe33d5b1 Patch
- https://lore.kernel.org/linux-cve-announce/2024052111-CVE-2023-52840-8a3d@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52840
- https://www.cve.org/CVERecord?id=CVE-2023-52840
Change history (0)
No recorded changes yet.