CVE-2023-53454 Details
Description
In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.
A use-after-free vulnerability has been addressed in the Linux kernel's HID multitouch driver. The issue arose from incorrectly referencing the input device when allocating the input device name, which could lead to a use-after-free condition. This occurred when the input device was unregistered, freeing the name before it was needed for a uevent. The vulnerability has been fixed by changing the reference to the HID device and using a more straightforward memory allocation method. This vulnerability affects several versions of the Linux kernel.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/15ec7cb55e7d88755aa01d44a7a1015a42bfce86 | kernel.org | Patch |
| https://git.kernel.org/stable/c/1d7833db9fd118415dace2ca157bfa603dec9c8c | kernel.org | Patch |
| https://git.kernel.org/stable/c/2763732ec1e68910719c75b6b896e11b6d3d622b | kernel.org | Patch |
| https://git.kernel.org/stable/c/39c70c19456e50dcb3abfe53539220dff0490f1d | kernel.org | Patch |
| https://git.kernel.org/stable/c/4794394635293a3e74591351fff469cea7ad15a2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ac0d389402a6ff9ad92cea02c2d8c711483b91ab | kernel.org | Patch |
| https://git.kernel.org/stable/c/b70ac7849248ec8128fa12f86e3655ba38838f29 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dde88ab4e45beb60b217026207aa9c14c88d71ab | kernel.org | Patch |
| https://git.kernel.org/stable/c/df7ca43fe090e1a56c216c8ebc106ef5fd49afc6 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.12, < 4.14.326 >= 4.15, < 4.19.295 >= 4.20, < 5.4.257 >= 5.5, < 5.10.195 >= 5.11, < 5.15.132 >= 5.16, < 6.1.53 >= 6.2, < 6.4.16 >= 6.5, < 6.5.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 16, 2026 | Initial Analysis | [email protected] |
| Oct 1, 2025 | New CVE Received | kernel.org |