cbcvebase.
CVE-2023-53003
published 2025-03-27

CVE-2023-53003: In the Linux kernel, the following vulnerability has been resolved: EDAC/qcom: Do not pass llcc_driv_data as edac_device_ctl_info's pvt_info The memory for…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.6th percentile
In the Linux kernel, the following vulnerability has been resolved: EDAC/qcom: Do not pass llcc_driv_data as edac_device_ctl_info's pvt_info The memory for llcc_driv_data is allocated by the LLCC driver. But when it is passed as the private driver info to the EDAC core, it will get freed during the qcom_edac driver release. So when the qcom_edac driver gets probed again, it will try to use the freed data leading to the use-after-free bug. Hence, do not pass llcc_driv_data as pvt_info but rather reference it using the platform_data pointer in the qcom_edac driver.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= 27450653f1db0b9d5b5048a246c850c52ee4aa61 < 66e10d5f399629ef7877304d9ba2b35d0474e7eb66e10d5f399629ef7877304d9ba2b35d0474e7eb
linuxlinux>= 27450653f1db0b9d5b5048a246c850c52ee4aa61 < 76d9ebb7f0bc10fbc78b6d576751552edf74396876d9ebb7f0bc10fbc78b6d576751552edf743968
linuxlinux>= 27450653f1db0b9d5b5048a246c850c52ee4aa61 < bff5243bd32661cf9ce66f6d9210fc8f89bda145bff5243bd32661cf9ce66f6d9210fc8f89bda145
linuxlinux>= 27450653f1db0b9d5b5048a246c850c52ee4aa61 < 6f0351d0c311951b8b3064db91e61841e85b2b966f0351d0c311951b8b3064db91e61841e85b2b96
linuxlinux>= 27450653f1db0b9d5b5048a246c850c52ee4aa61 < 977c6ba624f24ae20cf0faee871257a39348d4a9977c6ba624f24ae20cf0faee871257a39348d4a9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 4.20 < 5.4.2315.4.231
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.5 < 5.10.1665.10.166

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.