CVE-2023-53472

EUVD-2025-32824
In the Linux kernel, the following vulnerability has been resolved:

pwm: lpc32xx: Remove handling of PWM channels

Because LPC32xx PWM controllers have only a single output which is
registered as the only PWM device/channel per controller, it is known in
advance that pwm->hwpwm value is always 0. On basis of this fact
simplify the code by removing operations with pwm->hwpwm, there is no
controls which require channel number as input.

Even though I wasn't aware at the time when I forward ported that patch,
this fixes a null pointer dereference as lpc32xx->chip.pwms is NULL
before devm_pwmchip_add() is called.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
4.9.284 ≤
𝑥
< 4.10
linuxlinux_kernel
4.14.248 ≤
𝑥
< 4.14.326
linuxlinux_kernel
4.19.208 ≤
𝑥
< 4.19.295
linuxlinux_kernel
5.4.149 ≤
𝑥
< 5.4.257
linuxlinux_kernel
5.10.69 ≤
𝑥
< 5.10.195
linuxlinux_kernel
5.14.8 ≤
𝑥
< 5.15.132
linuxlinux_kernel
5.16 ≤
𝑥
< 6.1.54
linuxlinux_kernel
6.2 ≤
𝑥
< 6.5.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.148-1
fixed
bookworm (security)
6.1.153-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.237-1
fixed
forky
6.16.8-1
fixed
sid
6.16.9-1
fixed
trixie
6.12.43-1
fixed
trixie (security)
6.12.48-1
fixed