cbcvebase.
CVE-2023-53472
published 2025-10-01

CVE-2023-53472: In the Linux kernel, the following vulnerability has been resolved: pwm: lpc32xx: Remove handling of PWM channels Because LPC32xx PWM controllers have only a…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: pwm: lpc32xx: Remove handling of PWM channels Because LPC32xx PWM controllers have only a single output which is registered as the only PWM device/channel per controller, it is known in advance that pwm->hwpwm value is always 0. On basis of this fact simplify the code by removing operations with pwm->hwpwm, there is no controls which require channel number as input. Even though I wasn't aware at the time when I forward ported that patch, this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL before devm_pwmchip_add() is called.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 322b70b522abe03cd59712bb47a72eddd835d19d < a2d9d884e84bfd37892219b1f55847f36d8e9901a2d9d884e84bfd37892219b1f55847f36d8e9901
linuxlinux>= 3d2813fb17e5fd0d73c1d1442ca0192bde4af10e < 5e22217c11424ef958ba28d03ff7167b4d7a89145e22217c11424ef958ba28d03ff7167b4d7a8914
linuxlinux>= 3d2813fb17e5fd0d73c1d1442ca0192bde4af10e < 523f6268e86552a048975749251184c4e9a4b38f523f6268e86552a048975749251184c4e9a4b38f
linuxlinux>= 3d2813fb17e5fd0d73c1d1442ca0192bde4af10e < e3a0ddbaf7f1f9ffc070718b417461ced3268758e3a0ddbaf7f1f9ffc070718b417461ced3268758
linuxlinux>= 3d2813fb17e5fd0d73c1d1442ca0192bde4af10e < 4aae44f65827f0213a7361cf9c32cfe06114473f4aae44f65827f0213a7361cf9c32cfe06114473f
linuxlinux>= 4.14.248 < 4.14.3264.14.326
linuxlinux>= 4.19.208 < 4.19.2954.19.295
linuxlinux>= 4.9.284 < 4.104.10
linuxlinux>= 4459118977665f681017e1299933895d54b6e87b < a9a505f5b39d8fff1a55963a5e524c84639e98b2a9a505f5b39d8fff1a55963a5e524c84639e98b2
linuxlinux>= 5.10.69 < 5.10.1955.10.195
linuxlinux>= 5.14.8 < 5.155.15
linuxlinux>= 5.4.149 < 5.4.2575.4.257
linuxlinux>= 81e6b51709da162b94e40a445bb60856406beaa1 < 04301da4d87067a989f70ee56942bf9d97cd2a4504301da4d87067a989f70ee56942bf9d97cd2a45
linuxlinux>= bb4de81eb940e7027f37a6fd3b7ddcb4403deb56 < abd9b2ee4047ccd980decbf26d61f9637604b1d5abd9b2ee4047ccd980decbf26d61f9637604b1d5
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 4.14.248 < 4.14.3264.14.326
linuxlinux_kernel>= 4.19.208 < 4.19.2954.19.295
linuxlinux_kernel>= 4.9.284 < 4.104.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.