CVE-2023-53219
published 2025-09-15CVE-2023-53219: In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: netup_unidvb: fix use-after-free at del_timer()
When Universal DVB card is detaching, netup_unidvb_dma_fini()
uses del_timer() to stop dma->timeout timer. But when timer
handler netup_unidvb_dma_timeout() is running, del_timer()
could not stop it. As a result, the use-after-free bug could
happen. The process is shown below:
(cleanup routine) | (timer routine)
| mod_timer(&dev->tx_sim_timer, ..)
netup_unidvb_finidev() | (wait a time)
netup_unidvb_dma_fini() | netup_unidvb_dma_timeout()
del_timer(&dma->timeout); |
| ndev->pci_dev->dev //USE
Fix by changing del_timer() to del_timer_sync().
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < dd5c77814f290b353917df329f36de1472d47154 | dd5c77814f290b353917df329f36de1472d47154 |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 90229e9ee957d4514425e4a4d82c50ab5d57ac4d | 90229e9ee957d4514425e4a4d82c50ab5d57ac4d |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 1550bcf2983ae1220cc8ab899a39a423fa7cb523 | 1550bcf2983ae1220cc8ab899a39a423fa7cb523 |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < f9982db735a8495eee14267cf193c806b957e942 | f9982db735a8495eee14267cf193c806b957e942 |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 051af3f0b7d1cd8ab7f3e2523ad8ae1af44caba3 | 051af3f0b7d1cd8ab7f3e2523ad8ae1af44caba3 |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 07821524f67bf920342bc84ae8b3dea2a315a89e | 07821524f67bf920342bc84ae8b3dea2a315a89e |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < c8f9c05e1ebcc9c7bc211cc8b74d8fb86a8756fc | c8f9c05e1ebcc9c7bc211cc8b74d8fb86a8756fc |
| linux | linux | >= 52b1eaf4c59a3bbd07afbb4ab4f43418a807d02e < 0f5bb36bf9b39a2a96e730bf4455095b50713f63 | 0f5bb36bf9b39a2a96e730bf4455095b50713f63 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.15 < 4.19.284 | 4.19.284 |
| linux | linux_kernel | >= 4.20 < 5.4.244 | 5.4.244 |
| linux | linux_kernel | >= 4.3 < 4.14.316 | 4.14.316 |
| linux | linux_kernel | >= 5.11 < 5.15.113 | 5.15.113 |
| linux | linux_kernel | >= 5.16 < 6.1.30 | 6.1.30 |
| linux | linux_kernel | >= 5.5 < 5.10.181 | 5.10.181 |
| linux | linux_kernel | >= 6.2 < 6.3.4 | 6.3.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53219: In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is
osv·2025-09-15·CVSS 7.8
CVE-2023-53219 [HIGH] CVE-2023-53219: In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is
In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is detaching, netup_unidvb_dma_fini() uses del_timer() to stop dma->timeout timer. But when timer handler netup_unidvb_dma_timeout() is running, del_timer() could not stop it. As a result, the use-after-free bug could happen. The process is shown below: (cleanup routine) | (timer routine) | mod_timer(&dev->tx_sim_timer, ..) netup_unidvb_finidev() | (wait a time) netup_unidvb_dma_fini() | netup_unidvb_dma_timeout() del_timer(&dma->timeout); | | ndev->pci_dev->dev //USE Fix by changing del_timer() to del_timer_sync().
GHSA
GHSA-76f5-923v-9jc3: In the Linux kernel, the following vulnerability has been resolved:
media: netup_unidvb: fix use-after-free at del_timer()
When Universal DVB card i
ghsa_unreviewed·2025-09-15
CVE-2023-53219 [HIGH] CWE-416 GHSA-76f5-923v-9jc3: In the Linux kernel, the following vulnerability has been resolved:
media: netup_unidvb: fix use-after-free at del_timer()
When Universal DVB card i
In the Linux kernel, the following vulnerability has been resolved:
media: netup_unidvb: fix use-after-free at del_timer()
When Universal DVB card is detaching, netup_unidvb_dma_fini()
uses del_timer() to stop dma->timeout timer. But when timer
handler netup_unidvb_dma_timeout() is running, del_timer()
could not stop it. As a result, the use-after-free bug could
happen. The process is shown below:
(cleanup routine) | (timer routine)
| mod_timer(&dev->tx_sim_timer, ..)
netup_unidvb_finidev() | (wait a time)
netup_unidvb_dma_fini() | netup_unidvb_dma_timeout()
del_timer(&dma->timeout); |
| ndev->pci_dev->dev //USE
Fix by changing del_timer() to del_timer_sync().
Red Hat
kernel: media: netup_unidvb: fix use-after-free at del_timer()
vendor_redhat·2025-09-15·CVSS 7.8
CVE-2023-53219 [HIGH] kernel: media: netup_unidvb: fix use-after-free at del_timer()
kernel: media: netup_unidvb: fix use-after-free at del_timer()
In the Linux kernel, the following vulnerability has been resolved:
media: netup_unidvb: fix use-after-free at del_timer()
When Universal DVB card is detaching, netup_unidvb_dma_fini()
uses del_timer() to stop dma->timeout timer. But when timer
handler netup_unidvb_dma_timeout() is running, del_timer()
could not stop it. As a result, the use-after-free bug could
happen. The process is shown below:
(cleanup routine) | (timer routine)
| mod_timer(&dev->tx_sim_timer, ..)
netup_unidvb_finidev() | (wait a time)
netup_unidvb_dma_fini() | netup_unidvb_dma_timeout()
del_timer(&dma->timeout); |
| ndev->pci_dev->dev //USE
Fix by changing del_timer() to del_timer_sync().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Pack
Debian
CVE-2023-53219: linux - In the Linux kernel, the following vulnerability has been resolved: media: netu...
vendor_debian·2023·CVSS 7.8
CVE-2023-53219 [HIGH] CVE-2023-53219: linux - In the Linux kernel, the following vulnerability has been resolved: media: netu...
In the Linux kernel, the following vulnerability has been resolved: media: netup_unidvb: fix use-after-free at del_timer() When Universal DVB card is detaching, netup_unidvb_dma_fini() uses del_timer() to stop dma->timeout timer. But when timer handler netup_unidvb_dma_timeout() is running, del_timer() could not stop it. As a result, the use-after-free bug could happen. The process is shown below: (cleanup routine) | (timer routine) | mod_timer(&dev->tx_sim_timer, ..) netup_unidvb_finidev() | (wait a time) netup_unidvb_dma_fini() | netup_unidvb_dma_timeout() del_timer(&dma->timeout); | | ndev->pci_dev->dev //USE Fix by changing del_timer() to del_timer_sync().
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/051af3f0b7d1cd8ab7f3e2523ad8ae1af44caba3https://git.kernel.org/stable/c/07821524f67bf920342bc84ae8b3dea2a315a89ehttps://git.kernel.org/stable/c/0f5bb36bf9b39a2a96e730bf4455095b50713f63https://git.kernel.org/stable/c/1550bcf2983ae1220cc8ab899a39a423fa7cb523https://git.kernel.org/stable/c/90229e9ee957d4514425e4a4d82c50ab5d57ac4dhttps://git.kernel.org/stable/c/c8f9c05e1ebcc9c7bc211cc8b74d8fb86a8756fchttps://git.kernel.org/stable/c/dd5c77814f290b353917df329f36de1472d47154https://git.kernel.org/stable/c/f9982db735a8495eee14267cf193c806b957e942
2025-09-15
Published