CVE-2023-53389

Source
https://cve.org/CVERecord?id=CVE-2023-53389
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53389.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53389
Downstream
Published
2025-09-18T13:33:32.095Z
Modified
2026-03-11T20:52:08.192764Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
drm/mediatek: dp: Only trigger DRM HPD events if bridge is attached
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/mediatek: dp: Only trigger DRM HPD events if bridge is attached

The MediaTek DisplayPort interface bridge driver starts its interrupts as soon as its probed. However when the interrupts trigger the bridge might not have been attached to a DRM device. As drmhelperhpdirqevent() does not check whether the passed in drm_device is valid or not, a NULL pointer passed in results in a kernel NULL pointer dereference in it.

Check whether the bridge is attached and only trigger an HPD event if it is.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53389.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f70ac097a2cf5d4b67b2c1bbb73196c573ffcb7b
Fixed
6524d3d58797975cc40b85be1e9b89721b4e8d0b
Fixed
3551789d0635dfb2df8ab8e7fdbf0647e9c1724c
Fixed
d1c04e338016ae2517c641806a831b1f3eee2bed
Fixed
36b617f7e4ae663fcadd202ea061ca695ca75539

Affected versions

v5.*
v5.19
v5.19-rc7
v5.19-rc8
v6.*
v6.0
v6.0-rc1
v6.0-rc2
v6.0-rc3
v6.0-rc4
v6.0-rc5
v6.0-rc6
v6.0-rc7
v6.1
v6.1-rc1
v6.1-rc2
v6.1-rc3
v6.1-rc4
v6.1-rc5
v6.1-rc6
v6.1-rc7
v6.1-rc8
v6.1.1
v6.1.10
v6.1.11
v6.1.12
v6.1.13
v6.1.14
v6.1.15
v6.1.16
v6.1.17
v6.1.18
v6.1.19
v6.1.2
v6.1.20
v6.1.21
v6.1.22
v6.1.23
v6.1.24
v6.1.25
v6.1.26
v6.1.27
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.1.7
v6.1.8
v6.1.9
v6.2
v6.2-rc1
v6.2-rc2
v6.2-rc3
v6.2-rc4
v6.2-rc5
v6.2-rc6
v6.2-rc7
v6.2-rc8
v6.2.1
v6.2.10
v6.2.11
v6.2.12
v6.2.13
v6.2.14
v6.2.2
v6.2.3
v6.2.4
v6.2.5
v6.2.6
v6.2.7
v6.2.8
v6.2.9
v6.3
v6.3-rc1
v6.3-rc2
v6.3-rc3
v6.3-rc4
v6.3-rc5
v6.3-rc6
v6.3-rc7
v6.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53389.json"
vanir_signatures
[
    {
        "id": "CVE-2023-53389-321707cb",
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "292890511188341734087611052985964722702",
                "157751464972367471914688626357233344604",
                "4952024218176198831066378770497877515",
                "114282708121298302998888870180202945246"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "drivers/gpu/drm/mediatek/mtk_dp.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36b617f7e4ae663fcadd202ea061ca695ca75539",
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2023-53389-9d7c6491",
        "signature_type": "Function",
        "digest": {
            "function_hash": "2377753579671161984052373755449736638",
            "length": 823.0
        },
        "target": {
            "file": "drivers/gpu/drm/mediatek/mtk_dp.c",
            "function": "mtk_dp_hpd_event_thread"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36b617f7e4ae663fcadd202ea061ca695ca75539",
        "signature_version": "v1",
        "deprecated": false
    }
]