cbcvebase.
CVE-2023-53842
published 2025-12-09

CVE-2023-53842: In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove The MBHC resources must…

PriorityP421low5.5
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove The MBHC resources must be released on component probe failure and removal so can not be tied to the lifetime of the component device. This is specifically needed to allow probe deferrals of the sound card which otherwise fails when reprobing the codec component: snd-sc8280xp sound: ASoC: failed to instantiate card -517 genirq: Flags mismatch irq 299. 00002001 (mbhc sw intr) vs. 00002001 (mbhc sw intr) wcd938x_codec audio-codec: Failed to request mbhc interrupts -16 wcd938x_codec audio-codec: mbhc initialization failed wcd938x_codec audio-codec: ASoC: error at snd_soc_component_probe on audio-codec: -16 snd-sc8280xp sound: ASoC: failed to instantiate card -16

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 < 90ab6446eb522e31421b77bf8f45714f5668f9a390ab6446eb522e31421b77bf8f45714f5668f9a3
linuxlinux>= 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 < 17feff71d06c96dea1fa72451c20d411e9d5ac8f17feff71d06c96dea1fa72451c20d411e9d5ac8f
linuxlinux>= 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 < ce4059e1c0aca972446e06c09ee09a0d2ba5df54ce4059e1c0aca972446e06c09ee09a0d2ba5df54
linuxlinux>= 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 < a5475829adcc600bc69ee9ff7c9e3e43fb4f8d30a5475829adcc600bc69ee9ff7c9e3e43fb4f8d30
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.14.0 < 5.15.1235.15.123
linuxlinux_kernel>= 5.16.0 < 6.1.426.1.42
linuxlinux_kernel>= 6.2.0 < 6.4.76.4.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.