{"id":"CVE-2023-52439","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nuio: Fix use-after-free in uio_open\n\ncore-1\t\t\t\tcore-2\n-------------------------------------------------------\nuio_unregister_device\t\tuio_open\n\t\t\t\tidev = idr_find()\ndevi…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nuio: Fix use-after-free in uio_open\n\ncore-1\t\t\t\tcore-2\n-------------------------------------------------------\nuio_unregister_device\t\tuio_open\n\t\t\t\tidev = idr_find()\ndevi…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-415"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel > 4.18.0, < 4.19.306","linux_kernel >= 4.20.0, < 5.4.268","linux_kernel >= 5.5.0, < 5.10.209","linux_kernel >= 5.11.0, < 5.15.148","linux_kernel >= 5.16.0, < 6.1.74","linux_kernel >= 6.2.0, < 6.6.13","linux_kernel >= 6.7.0, < 6.7.1","linux_kernel = 4.18"],"patched":["linux_kernel 6.7.1"],"published":"2024-02-20","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-52439","references":[{"url":"https://git.kernel.org/stable/c/0c9ae0b8605078eafc3bea053cc78791e97ba2e2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/17a8519cb359c3b483fb5c7367efa9a8a508bdea","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3174e0f7de1ba392dc191625da83df02d695b60c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35f102607054faafe78d2a6994b18d5d9d6e92ad","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cf604ee538ed0c467abe3b4cda5308a6398f0f7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e0be1229ae199ebb90b33102f74a0f22d152570","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/913205930da6213305616ac539447702eaa85e41","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e93da893d52d82d57fc0db2ca566024e0f26ff50","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0c9ae0b8605078eafc3bea053cc78791e97ba2e2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/17a8519cb359c3b483fb5c7367efa9a8a508bdea","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/3174e0f7de1ba392dc191625da83df02d695b60c","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/35f102607054faafe78d2a6994b18d5d9d6e92ad","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/5cf604ee538ed0c467abe3b4cda5308a6398f0f7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/5e0be1229ae199ebb90b33102f74a0f22d152570","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/913205930da6213305616ac539447702eaa85e41","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/e93da893d52d82d57fc0db2ca566024e0f26ff50","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00016.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20241227-0006/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00299,"epssPercentile":0.22799,"ingestedAt":"2026-08-04T10:39:37.431Z","slug":"CVE-2023-52439","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nuio: Fix use-after-free in uio_open\n\ncore-1\t\t\t\tcore-2\n-------------------------------------------------------\nuio_unregister_device\t\tuio_open\n\t\t\t\tidev = idr_find()\ndevice_unregister(&idev->dev)\nput_device(&idev->dev)\nuio_device_release\n\t\t\t\tget_device(&idev->dev)\nkfree(idev)\nuio_free_minor(minor)\n\t\t\t\tuio_release\n\t\t\t\tput_device(&idev->dev)\n\t\t\t\tkfree(idev)\n-------------------------------------------------------\n\nIn the core-1 uio_unregister_device(), the device_unregister will kfree\nidev when the idev->dev kobject ref is 1. But after core-1\ndevice_unregister, put_device and before doing kfree, the core-2 may\nget_device. Then:\n1. After core-1 kfree idev, the core-2 will do use-after-free for idev.\n2. When core-2 do uio_release and put_device, the idev will be double\n   freed.\n\nTo address this issue, we can get idev atomic & inc idev reference with\nminor_lock.\n\n## Affected\n\n- `linux_kernel > 4.18.0, < 4.19.306`\n- `linux_kernel >= 4.20.0, < 5.4.268`\n- `linux_kernel >= 5.5.0, < 5.10.209`\n- `linux_kernel >= 5.11.0, < 5.15.148`\n- `linux_kernel >= 5.16.0, < 6.1.74`\n- `linux_kernel >= 6.2.0, < 6.6.13`\n- `linux_kernel >= 6.7.0, < 6.7.1`\n- `linux_kernel = 4.18`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.7.1`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}