In the Linux kernel, the following vulnerability has been resolved:
HID: uclogic: Correct devm device reference for hidinput input_dev name
Reference the HID device rather than the input device for the devm
allocation of the input_dev name. Referencing the input_dev would lead to a
use-after-free when the input_dev was unregistered and subsequently fires a
uevent that depends on the name. At the point of firing the uevent, the
name would be freed by devres management.
Use devm_kasprintf to simplify the logic for allocating memory and
formatting the input_dev name string.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-30 13:16
Updated : 2026-06-17 06:47
NVD link : CVE-2023-54207
Mitre link : CVE-2023-54207
CVE.ORG link : CVE-2023-54207
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
