From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F1477446B4 for ; Tue, 21 May 2024 15:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716305905; cv=none; b=NSYm5495vIsCGTHMfKEP7KWRv58pkl7e3B6jshZFxq3H+B0joWkJ4ND5rqwM4tQL39CcUGHiXcelkxKfFHZUVMcHEXH8cqfEyUw6ZAiF5gfqohA9g/BWGAGwQ2Fgn6J8M77CKTSmjL9uU3pAKj/qOo5LfbLjGzxQ6wNDDmKy3vw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1716305905; c=relaxed/simple; bh=s2Mhd3a/u18hjOxEIV3rDcjD6L/j8RnMVjFWyrRYSKc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uNxjWE+wANNshtYEu/0PRxIIn5vCwVvKS9ElU+7GUdooOD3xTUrmUIt8bX/miWsfJ//ueGEKA9C1pk3mLFX9rGBnetvdy18JEoO/reVSzUmJuDgshEebPgrSL5jHRIJDUYFQIwlzFMhwdgorA+dmIzsoybVdTI04T7ty7QNO/MQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=mPeakmQX; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="mPeakmQX" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7D1AFC2BD11; Tue, 21 May 2024 15:38:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1716305904; bh=s2Mhd3a/u18hjOxEIV3rDcjD6L/j8RnMVjFWyrRYSKc=; h=From:To:Cc:Subject:Date:Reply-to:From; b=mPeakmQXOznYbJp+oTk6p1nIxpuvVRIj0LbByLQQyvTCt5fG+1xlHk7NKvAGbMCi7 jIxuK80LljRK+cpqoaZrwOXCkFJWiOOq+fjt7VP7NnhLbwtfRAmawQuiQcZDChQjr7 xtL6vIPMigZ/BU5Jrtq/J8CxuRha/f9js52tdeTI= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2023-52840: Input: synaptics-rmi4 - fix use after free in rmi_unregister_function() Date: Tue, 21 May 2024 17:32:16 +0200 Message-ID: <2024052111-CVE-2023-52840-8a3d@gregkh> X-Mailer: git-send-email 2.45.1 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2893; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=s2Mhd3a/u18hjOxEIV3rDcjD6L/j8RnMVjFWyrRYSKc=; b=owGbwMvMwCRo6H6F97bub03G02pJDGk+++xXTY/osW+Xk5vlkl/hXFvWcftvw2rt8wIx0jekN BJrlLw7YlkYBJkYZMUUWb5s4zm6v+KQopeh7WmYOaxMIEMYuDgFYCJXWBkWNHWVThC8fejuoo9G r27HThBKzxUyYliw55ubpDe/8yfnbOVtsVVrZ+aXM6wEAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix use after free in rmi_unregister_function() The put_device() calls rmi_release_function() which frees "fn" so the dereference on the next line "fn->num_of_irqs" is a use after free. Move the put_device() to the end to fix this. The Linux kernel CVE team has assigned CVE-2023-52840 to this issue. Affected and fixed versions =========================== Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 4.19.299 with commit 2f236d8638f5 Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 5.4.261 with commit 50d122536661 Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 5.10.201 with commit 6c71e065befb Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 5.15.139 with commit 303766bb92c5 Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 6.1.63 with commit 7082b1fb5321 Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 6.5.12 with commit cc56c4d17721 Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 6.6.2 with commit c8e639f5743c Issue introduced in 4.18 with commit 24d28e4f1271 and fixed in 6.7 with commit eb988e46da2e Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2023-52840 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/input/rmi4/rmi_bus.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2f236d8638f5b43e0c72919a6a27fe286c32053f https://git.kernel.org/stable/c/50d12253666195a14c6cd2b81c376e2dbeedbdff https://git.kernel.org/stable/c/6c71e065befb2fae8f1461559b940c04e1071bd5 https://git.kernel.org/stable/c/303766bb92c5c225cf40f9bbbe7e29749406e2f2 https://git.kernel.org/stable/c/7082b1fb5321037bc11ba1cf2d7ed23c6b2b521f https://git.kernel.org/stable/c/cc56c4d17721dcb10ad4e9c9266e449be1462683 https://git.kernel.org/stable/c/c8e639f5743cf4b01f8c65e0df075fe4d782b585 https://git.kernel.org/stable/c/eb988e46da2e4eae89f5337e047ce372fe33d5b1