Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-54026— opp: Fix use-after-free in lazy_opp_tables after probe deferral

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.16% · P6

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux7eba0c7641b0009818e469dbfcdd87a0155ab9d4< 39a0e723d3502f6dc4c603f57ebe8dc7bcc4a4bcaffected
7eba0c7641b0009818e469dbfcdd87a0155ab9d4< 76ab057de777723ec924654502d1a260ba7d7d54affected
7eba0c7641b0009818e469dbfcdd87a0155ab9d4< c05e76d6b249e5254c31994eedd06dd3cc90dee0affected
7eba0c7641b0009818e469dbfcdd87a0155ab9d4< b2a2ab039bd58f51355e33d7d3fc64605d7f870daffected
5.12affected
< 5.12unaffected
5.15.121≤ 5.15.*unaffected
6.1.40≤ 6.1.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-54026

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
opp: Fix use-after-free in lazy_opp_tables after probe deferral
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: opp: Fix use-after-free in lazy_opp_tables after probe deferral When dev_pm_opp_of_find_icc_paths() in _allocate_opp_table() returns -EPROBE_DEFER, the opp_table is freed again, to wait until all the interconnect paths are available. However, if the OPP table is using required-opps then it may already have been added to the global lazy_opp_tables list. The error path does not remove the opp_table from the list again. This can cause crashes later when the provider of the required-opps is added, since we will iterate over OPP tables that have already been freed. E.g.: Unable to handle kernel NULL pointer dereference when read CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.4.0-rc3 PC is at _of_add_opp_table_v2 (include/linux/of.h:949 drivers/opp/of.c:98 drivers/opp/of.c:344 drivers/opp/of.c:404 drivers/opp/of.c:1032) -> lazy_link_required_opp_table() Fix this by calling _of_clear_opp_table() to remove the opp_table from the list and clear other allocated resources. While at it, also add the missing mutex_destroy() calls in the error path.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于opp框架在探测延迟后未从全局列表中移除opp表,可能导致释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7eba0c7641b0009818e469dbfcdd87a0155ab9d4 ~ 39a0e723d3502f6dc4c603f57ebe8dc7bcc4a4bc -
LinuxLinux 5.12 -

II. Public POCs for CVE-2023-54026

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54026

登录查看更多情报信息。

Other References for CVE-2023-54026 (2)

Same Patch Batch · Linux · 2025-12-24 · 322 CVEs total

CVE-2025-687459.8 CRITICALscsi: qla2xxx: Clear cmds after chip reset
CVE-2025-687269.8 CRITICALcrypto: aead - Fix reqsize handling
CVE-2025-687419.8 CRITICALscsi: qla2xxx: Fix improper freeing of purex item
CVE-2025-683599.8 CRITICALbtrfs: fix double free of qgroup record after failure to add delayed ref head
CVE-2025-687368.8 HIGHlandlock: Fix handling of disconnected directories
CVE-2025-683658.2 HIGHfs/ntfs3: Initialize allocated memory before use
CVE-2025-683608.2 HIGHwifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks
CVE-2025-687467.8 HIGHspi: tegra210-quad: Fix timeout handling
CVE-2025-683797.8 HIGHRDMA/rxe: Fix null deref on srq->rq.queue after resize failure
CVE-2025-683707.8 HIGHcoresight: tmc: add the handle of the event to the path
CVE-2025-687247.8 HIGHcrypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
CVE-2025-687357.8 HIGHdrm/panthor: Prevent potential UAF in group creation
CVE-2025-687307.8 HIGHaccel/ivpu: Fix page fault in ivpu_bo_unbind_all_bos_from_context()
CVE-2025-687487.8 HIGHdrm/panthor: Fix UAF race between device unplug and FW event processing
CVE-2025-683477.8 HIGHALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
CVE-2025-683527.8 HIGHspi: ch341: fix out-of-bounds memory access in ch341_transfer_one
CVE-2025-687497.8 HIGHaccel/ivpu: Fix race condition when unbinding BOs
CVE-2025-687477.8 HIGHdrm/panthor: Fix UAF on kernel BO VA nodes
CVE-2025-683497.5 HIGHNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
CVE-2025-683697.5 HIGHntfs3: init run lock for extend inode

Showing top 20 of 322 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-54026

No comments yet


Leave a comment