cbcvebase.
CVE-2023-54245
published 2025-12-30

CVE-2023-54245: In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds When we run syzkaller we get…

PriorityP422low5.5
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds When we run syzkaller we get below Out of Bound. "KASAN: slab-out-of-bounds Read in regcache_flat_read" Below is the backtrace of the issue: dump_backtrace+0x0/0x4c8 show_stack+0x34/0x44 dump_stack_lvl+0xd8/0x118 print_address_description+0x30/0x2d8 kasan_report+0x158/0x198 __asan_report_load4_noabort+0x44/0x50 regcache_flat_read+0x10c/0x110 regcache_read+0xf4/0x180 _regmap_read+0xc4/0x278 _regmap_update_bits+0x130/0x290 regmap_update_bits_base+0xc0/0x15c snd_soc_component_update_bits+0xa8/0x22c snd_soc_component_write_field+0x68/0xd4 tx_macro_digital_mute+0xec/0x140 Actually There is no need to have decimator with 32 bits. By limiting the variable with short type u8 issue is resolved.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5 < da35a4e6eee5d73886312e85322a6e97df901987da35a4e6eee5d73886312e85322a6e97df901987
linuxlinux>= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5 < 57f9a9a232bde7abfe49c3072b29a255da9ba89157f9a9a232bde7abfe49c3072b29a255da9ba891
linuxlinux>= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5 < b0cd740a31412340fead50e69e4fe9bc3781c754b0cd740a31412340fead50e69e4fe9bc3781c754
linuxlinux>= d207bdea0ca9efde321ff142e9b9f2ef73f9cdf5 < e5e7e398f6bb7918dab0612eb6991f7bae95520de5e7e398f6bb7918dab0612eb6991f7bae95520d
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.12.0 < 5.15.1065.15.106
linuxlinux_kernel>= 5.16.0 < 6.1.236.1.23
linuxlinux_kernel>= 6.2.0 < 6.2.106.2.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.