cbcvebase.
CVE-2023-53275
published 2025-09-16

CVE-2023-53275: In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: fix a possible null-pointer dereference due to data race in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() The variable codec->regmap is often protected by the lock codec->regmap_lock when is accessed. However, it is accessed without holding the lock when is accessed in snd_hdac_regmap_sync(): if (codec->regmap) In my opinion, this may be a harmful race, because if codec->regmap is set to NULL right after the condition is checked, a null-pointer dereference can occur in the called function regcache_sync(): map->lock(map->lock_arg); --> Line 360 in drivers/base/regmap/regcache.c To fix this possible null-pointer dereference caused by data race, the mutex_lock coverage is extended to protect the if statement as well as the function call to regcache_sync(). [ Note: the lack of the regmap_lock itself is harmless for the current codec driver implementations, as snd_hdac_regmap_sync() is only for PM runtime resume that is prohibited during the codec probe. But the change makes the whole code more consistent, so it's merged as is -- tiwai ]

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 1a462be52f4505a2719631fb5aa7bfdbd37bfd8d < 9f9eed451176ffcac6b5ba0f6dae1a6b4a1cb0eb9f9eed451176ffcac6b5ba0f6dae1a6b4a1cb0eb
linuxlinux>= 1a462be52f4505a2719631fb5aa7bfdbd37bfd8d < 8703b26387e1fa4f8749db98d24c67617b873acb8703b26387e1fa4f8749db98d24c67617b873acb
linuxlinux>= 1a462be52f4505a2719631fb5aa7bfdbd37bfd8d < cdd412b528dee6e0851c4735d6676ec138da13a4cdd412b528dee6e0851c4735d6676ec138da13a4
linuxlinux>= 1a462be52f4505a2719631fb5aa7bfdbd37bfd8d < b32e40379e5b2814de0c4bc199edc2d82317dc07b32e40379e5b2814de0c4bc199edc2d82317dc07
linuxlinux>= 1a462be52f4505a2719631fb5aa7bfdbd37bfd8d < 1f4a08fed450db87fbb5ff5105354158bdbe1a221f4a08fed450db87fbb5ff5105354158bdbe1a22
linuxlinux>= 5.4.43 < 5.4.2555.4.255
linuxlinux>= 69d5dc286d05441ca2f854ae8df11201f6f9b706 < 109f0aaa0b8838a88af9125b79579023539300a7109f0aaa0b8838a88af9125b79579023539300a7
linuxlinux_kernel< 5.4.2555.4.255
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 5.11 < 5.15.1285.15.128
linuxlinux_kernel>= 5.16 < 6.1.476.1.47
linuxlinux_kernel>= 5.5 < 5.10.1925.10.192
linuxlinux_kernel>= 6.2 < 6.4.126.4.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.