cbcvebase.
CVE-2023-53219
published 2025-09-15

CVE-2023-53219: In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is detaching, netup_unidvb_dma_fini() uses del_timer() to stop dma->timeout timer. But when timer handler netup_unidvb_dma_timeout() is running, del_timer() could not stop it. As a result, the use-after-free bug could happen. The process is shown below: (cleanup routine) | (timer routine) | mod_timer(&dev->tx_sim_timer, ..) netup_unidvb_finidev() | (wait a time) netup_unidvb_dma_fini() | netup_unidvb_dma_timeout() del_timer(&dma->timeout); | | ndev->pci_dev->dev //USE Fix by changing del_timer() to del_timer_sync().

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < dd5c77814f290b353917df329f36de1472d47154dd5c77814f290b353917df329f36de1472d47154
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 90229e9ee957d4514425e4a4d82c50ab5d57ac4d90229e9ee957d4514425e4a4d82c50ab5d57ac4d
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 1550bcf2983ae1220cc8ab899a39a423fa7cb5231550bcf2983ae1220cc8ab899a39a423fa7cb523
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < f9982db735a8495eee14267cf193c806b957e942f9982db735a8495eee14267cf193c806b957e942
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 051af3f0b7d1cd8ab7f3e2523ad8ae1af44caba3051af3f0b7d1cd8ab7f3e2523ad8ae1af44caba3
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 07821524f67bf920342bc84ae8b3dea2a315a89e07821524f67bf920342bc84ae8b3dea2a315a89e
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < c8f9c05e1ebcc9c7bc211cc8b74d8fb86a8756fcc8f9c05e1ebcc9c7bc211cc8b74d8fb86a8756fc
linuxlinux>= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 0f5bb36bf9b39a2a96e730bf4455095b50713f630f5bb36bf9b39a2a96e730bf4455095b50713f63
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.15 < 4.19.2844.19.284
linuxlinux_kernel>= 4.20 < 5.4.2445.4.244
linuxlinux_kernel>= 4.3 < 4.14.3164.14.316
linuxlinux_kernel>= 5.11 < 5.15.1135.15.113
linuxlinux_kernel>= 5.16 < 6.1.306.1.30
linuxlinux_kernel>= 5.5 < 5.10.1815.10.181
linuxlinux_kernel>= 6.2 < 6.3.46.3.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.