CVE-2023-53640

Source
https://cve.org/CVERecord?id=CVE-2023-53640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53640
Downstream
Related
Published
2025-10-07T15:19:40.348Z
Modified
2026-03-23T05:29:41.972481Z
Summary
ASoC: lpass: Fix for KASAN use_after_free out of bounds
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: lpass: Fix for KASAN useafterfree out of bounds

When we run syzkaller we get below Out of Bounds error.

"KASAN: slab-out-of-bounds Read in regcacheflatread"

Below is the backtrace of the issue:

BUG: KASAN: slab-out-of-bounds in regcacheflatread+0x10c/0x110 Read of size 4 at addr ffffff8088fbf714 by task syz-executor.4/14144 CPU: 6 PID: 14144 Comm: syz-executor.4 Tainted: G W Hardware name: Qualcomm Technologies, Inc. sc7280 CRD platform (rev5+) (DT) Call trace: dumpbacktrace+0x0/0x4ec showstack+0x34/0x50 dumpstacklvl+0xdc/0x11c printaddressdescription+0x30/0x2d8 kasan_report+0x178/0x1e4 _asanreportload4noabort+0x44/0x50 regcacheflatread+0x10c/0x110 regcacheread+0xf8/0x5a0 regmapread+0x45c/0x86c regmapupdatebits+0x128/0x290 regmapupdatebitsbase+0xc0/0x15c sndsoccomponentupdatebits+0xa8/0x22c sndsoccomponentwritefield+0x68/0xd4 txmacroputdecenum+0x1d0/0x268 sndctlelemwrite+0x288/0x474

By Error checking and checking valid values issue gets rectifies.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53640.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c39667ddcfc516fee084e449179d54430a558298
Fixed
8f1512d78b5de928f4616a871e77b58fd546e651
Fixed
8d81d3b0ed3610d24191d24f8e9e20f6775f0cc5
Fixed
f5e61e3fe799ba2fda4320af23d26d28c3302045
Fixed
75e5fab7db0cecb6e16b22c34608f0b40a4c7cd1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53640.json"