PT-2023-9551 · Linux+5 · Linux Kernel+5

Zheng Wang

·

Published

2023-11-23

·

Updated

2025-09-29

·

CVE-2023-52491

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free bug in the Linux kernel's mtk-jpeg component, specifically due to error path handling in mtk jpeg dec device run. This bug can be triggered in two ways: by removing the module, which calls mtk jpeg remove for cleanup, or by closing the file descriptor, which calls mtk jpeg release. The bug causes a use-after-free condition because the mtk jpeg job timeout work function is started while the job is marked as finished by invoking v4l2 m2m job finish. The fix involves starting the timeout worker only if the jpegdec worker is started successfully, ensuring that v4l2 m2m job finish is only called in either mtk jpeg job timeout work or mtk jpeg dec device run.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-3457
BDU:2024-08401
CVE-2023-52491
DLA-3842-1
DSA-5681-1
OESA-2024-1498
OESA-2024-1499
OESA-2024-1500
OESA-2024-1501
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6795-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6828-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu