CVE-2023-54207 Details
Description
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hidinput input_dev name Reference the HID device rather than the input device for the devm allocation of the input_dev name. Referencing the input_dev would lead to a use-after-free when the input_dev was unregistered and subsequently fires a uevent that depends on the name. At the point of firing the uevent, the name would be freed by devres management. Use devm_kasprintf to simplify the logic for allocating memory and formatting the input_dev name string.
A use-after-free vulnerability has been identified in the Linux kernel's HID uclogic driver. This issue arises from incorrect management of device references for input device names. The vulnerability occurs when the input device is unregistered, freeing the name allocated for it. If a uevent is then triggered that relies on this name, it can lead to a use-after-free condition. The vulnerability affects the Linux kernel HID uclogic component, specifically in versions prior to the latest patch.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading the Linux kernel can be found in the official Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/4c2707dfee5847dc0b5ecfbe512c29c93832fdc4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/51f49e3927ad545cec0c0afb86856ccacd9f085d | kernel.org | Patch |
| https://git.kernel.org/stable/c/58f0d1c0e494a88f301bf455da7df4366f179bbb | kernel.org | Patch |
| https://git.kernel.org/stable/c/dd613a4e45f8d35f49a63a2064e5308fa5619e29 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f283805d984343b2f216e2f4c6c7af265b9542ae | kernel.org | Patch |
| https://git.kernel.org/stable/c/f78bb490b16ecb506d4904be4b00bf9aad6588f9 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.1, < 5.10.249 >= 5.11, < 5.15.199 >= 5.16, < 6.1.53 >= 6.2, < 6.4.16 >= 6.5, < 6.5.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 6, 2026 | CVE Modified | kernel.org |
| Dec 30, 2025 | New CVE Received | kernel.org |