cbcvebase.
CVE-2023-53388
published 2025-09-18

CVE-2023-53388: In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Clean dangling pointer on bind error path mtk_drm_bind() can fail, in which…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Clean dangling pointer on bind error path mtk_drm_bind() can fail, in which case drm_dev_put() is called, destroying the drm_device object. However a pointer to it was still being held in the private object, and that pointer would be passed along to DRM in mtk_drm_sys_prepare() if a suspend were triggered at that point, resulting in a panic. Clean the pointer when destroying the object in the error path to prevent this from happening.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < 9a48f99aa7bea15e0b1d8b0040c46b4792eddf3b9a48f99aa7bea15e0b1d8b0040c46b4792eddf3b
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < a161f1d92aabb3b8463f752bdc3474dc3a5ec0e5a161f1d92aabb3b8463f752bdc3474dc3a5ec0e5
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < 6a89ddee1686a8872384aaa9f0bcfa6b675acd866a89ddee1686a8872384aaa9f0bcfa6b675acd86
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < 49cf87919daeeeeeb9e924c39bdd9203af43446149cf87919daeeeeeb9e924c39bdd9203af434461
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < 7b551a501fa714890e55bae73efede1185728d727b551a501fa714890e55bae73efede1185728d72
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < f3887c771576c5d740c5c5b8bf654a8ab8020b7df3887c771576c5d740c5c5b8bf654a8ab8020b7d
linuxlinux>= 119f5173628aa7a0c3cf9db83460d40709e8241d < 36aa8c61af55675ed967900fbe5deb32d776f05136aa8c61af55675ed967900fbe5deb32d776f051
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 4.20 < 5.4.2355.4.235
linuxlinux_kernel>= 4.7 < 4.19.2764.19.276
linuxlinux_kernel>= 5.11 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 5.5 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.