CVE-2023-53314
EUVD-2023-5994716.09.2025, 17:15
In the Linux kernel, the following vulnerability has been resolved: fbdev/ep93xx-fb: Do not assign to struct fb_info.dev Do not assing the Linux device to struct fb_info.dev. The call to register_framebuffer() initializes the field to the fbdev device. Drivers should not override its value. Fixes a bug where the driver incorrectly decreases the hardware device's reference counter and leaks the fbdev device. v2: * add Fixes tag (Dan)Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| linux | linux_kernel | 2.6.32 ≤ 𝑥 < 4.14.326 |
| linux | linux_kernel | 4.15 ≤ 𝑥 < 4.19.295 |
| linux | linux_kernel | 4.20 ≤ 𝑥 < 5.4.257 |
| linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.195 |
| linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.132 |
| linux | linux_kernel | 5.16 ≤ 𝑥 < 6.1.54 |
| linux | linux_kernel | 6.2 ≤ 𝑥 < 6.5.4 |
𝑥
= Vulnerable software versions
Debian Releases
References