[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025120957-CVE-2023-53842-d1e7@gregkh>
Date: Tue, 9 Dec 2025 10:31:26 +0900
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...nel.org>
Subject: CVE-2023-53842: ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove
From: Greg Kroah-Hartman <gregkh@...nel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove
The MBHC resources must be released on component probe failure and
removal so can not be tied to the lifetime of the component device.
This is specifically needed to allow probe deferrals of the sound card
which otherwise fails when reprobing the codec component:
snd-sc8280xp sound: ASoC: failed to instantiate card -517
genirq: Flags mismatch irq 299. 00002001 (mbhc sw intr) vs. 00002001 (mbhc sw intr)
wcd938x_codec audio-codec: Failed to request mbhc interrupts -16
wcd938x_codec audio-codec: mbhc initialization failed
wcd938x_codec audio-codec: ASoC: error at snd_soc_component_probe on audio-codec: -16
snd-sc8280xp sound: ASoC: failed to instantiate card -16
The Linux kernel CVE team has assigned CVE-2023-53842 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.14 with commit 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 and fixed in 5.15.123 with commit 90ab6446eb522e31421b77bf8f45714f5668f9a3
Issue introduced in 5.14 with commit 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 and fixed in 6.1.42 with commit 17feff71d06c96dea1fa72451c20d411e9d5ac8f
Issue introduced in 5.14 with commit 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 and fixed in 6.4.7 with commit ce4059e1c0aca972446e06c09ee09a0d2ba5df54
Issue introduced in 5.14 with commit 0e5c9e7ff899808afa4e2b08c2e6ccc469bed681 and fixed in 6.5 with commit a5475829adcc600bc69ee9ff7c9e3e43fb4f8d30
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2023-53842
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
sound/soc/codecs/wcd-mbhc-v2.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/90ab6446eb522e31421b77bf8f45714f5668f9a3
https://git.kernel.org/stable/c/17feff71d06c96dea1fa72451c20d411e9d5ac8f
https://git.kernel.org/stable/c/ce4059e1c0aca972446e06c09ee09a0d2ba5df54
https://git.kernel.org/stable/c/a5475829adcc600bc69ee9ff7c9e3e43fb4f8d30
Powered by blists - more mailing lists