cbcvebase.
CVE-2023-54207
published 2025-12-30

CVE-2023-54207: In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Reference the HID…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < f78bb490b16ecb506d4904be4b00bf9aad6588f9f78bb490b16ecb506d4904be4b00bf9aad6588f9
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < 51f49e3927ad545cec0c0afb86856ccacd9f085d51f49e3927ad545cec0c0afb86856ccacd9f085d
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < f283805d984343b2f216e2f4c6c7af265b9542aef283805d984343b2f216e2f4c6c7af265b9542ae
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < 4c2707dfee5847dc0b5ecfbe512c29c93832fdc44c2707dfee5847dc0b5ecfbe512c29c93832fdc4
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < 58f0d1c0e494a88f301bf455da7df4366f179bbb58f0d1c0e494a88f301bf455da7df4366f179bbb
linuxlinux>= cce2dbdf258e6b27b2b100f511531edabb77f427 < dd613a4e45f8d35f49a63a2064e5308fa5619e29dd613a4e45f8d35f49a63a2064e5308fa5619e29
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 4.1 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.536.1.53
linuxlinux_kernel>= 6.2 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-5.15
ubuntulinux-gcp-fips
ubuntulinux-hwe-5.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.