PT-2025-40161 · Linux+2 · Linux Kernel+2

Published

2025-10-01

·

Updated

2026-01-28

·

CVE-2023-53454

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to HID multitouch devices. Specifically, an incorrect device reference for the hidinput input device name can lead to a use-after-free condition. This occurs when the input device is unregistered and a uevent is triggered, relying on a name that has already been freed by device resource management. The issue is addressed by referencing the HID device instead of the input device for device memory allocation and by using devm kasprintf to simplify memory allocation and string formatting for the input device name.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05903
CVE-2023-53454
OESA-2025-2554
OESA-2025-2659
SUSE-SU-2025:03600-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
SUSE-SU-2026:0316-1

Affected Products

Astra Linux
Linux Kernel
Suse