PT-2025-41084 · Linux+5 · Linux Kernel+5

Published

2023-05-17

·

Updated

2026-03-14

·

CVE-2023-53640

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the ASoC (Audio System on Chip) and lpass components. Specifically, the issue involves a use-after-free and out-of-bounds error detected by KASAN (Kernel Address Sanitizer) during testing with syzkaller. The error manifests as a "slab-out-of-bounds Read" in the regcache flat read function. The root cause is related to improper error checking and validation of values. The issue was identified and addressed through error checking and value validation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-03846
CVE-2023-53640
RHSA-2023:6583
RHSA-2023_6583
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4320-1

Affected Products

Asoc
Debian
Linux Kernel
Red Hat
Suse
Lpass