cbcvebase.
CVE-2023-53012
published 2025-03-27

CVE-2023-53012: In the Linux kernel, the following vulnerability has been resolved: thermal: core: call put_device() only after device_register() fails put_device() shouldn't…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal: core: call put_device() only after device_register() fails put_device() shouldn't be called before a prior call to device_register(). __thermal_cooling_device_register() doesn't follow that properly and needs fixing. Also thermal_cooling_device_destroy_sysfs() is getting called unnecessarily on few error paths. Fix all this by placing the calls at the right place. Based on initial work done by Caleb Connolly.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 108a6f91e2766a6d9142b1f2d90c07ac547eae7e < a7d736cc3c6cb0d7498bbfb56515d414e35e9510a7d736cc3c6cb0d7498bbfb56515d414e35e9510
linuxlinux>= 6.0.16 < 6.16.1
linuxlinux>= 80bb3b901abe6560620505e5c734d140c4f73a07 < 2846a7412f6246fd5171f51011bf76dfebcec0ee2846a7412f6246fd5171f51011bf76dfebcec0ee
linuxlinux>= c408b3d1d9bbc7de5fb0304fea424ef2539da616 < 6c54b7bc8a31ce0f7cc7f8deef05067df414f1d86c54b7bc8a31ce0f7cc7f8deef05067df414f1d8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 5.15.86 < 5.165.16
linuxlinux_kernel>= 6.0.16 < 6.16.1
linuxlinux_kernel>= 6.1.2 < 6.26.2
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.