CVE-2023-53612NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Simplify platform device handling Coretemp's platform driver is unconventional. All the real work is done globally by the initcall and CPU hotplug notifiers, while the "driver" effectively just wraps an allocation and the registration of the hwmon interface in a long-winded round-trip through the driver core. The whole logic of dynamically creating and destroying platform devices to bring the interfaces up an

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.105.4.235+4
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxe1b370b64031a01bb0c4158ce250073a88921fe14000384684f612b3645a944f6acde0e65ac370b8+6
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w3m2-4m45-q2fh: In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Simplify platform device handling Coretemp's platform driver i2025-10-04
OSV
CVE-2023-53612: In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Simplify platform device handling Coretemp's platform driver is2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: hwmon: (coretemp) Simplify platform device handling2025-10-04
Debian
CVE-2023-53612: linux - In the Linux kernel, the following vulnerability has been resolved: hwmon: (cor...2023