CVE-2023-54103

Source
https://cve.org/CVERecord?id=CVE-2023-54103
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54103.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-54103
Downstream
Published
2025-12-24T13:06:28Z
Modified
2026-04-10T05:07:04Z
Summary
media: mtk-jpeg: Fix use after free bug due to uncanceled work
Details

In the Linux kernel, the following vulnerability has been resolved:

media: mtk-jpeg: Fix use after free bug due to uncanceled work

In mtk_jpeg_probe, &jpeg->job_timeout_work is bound with mtk_jpeg_job_timeout_work. Then mtk_jpeg_dec_device_run and mtk_jpeg_enc_device_run may be called to start the work. If we remove the module which will call mtk_jpeg_remove to make cleanup, there may be a unfinished work. The possible sequence is as follows, which will cause a typical UAF bug.

Fix it by canceling the work before cleanup in the mtk_jpeg_remove

CPU0 CPU1

                |mtk_jpeg_job_timeout_work

mtk_jpeg_remove | v4l2_m2m_release | kfree(m2m_dev); | | | v4l2_m2m_get_curr_priv | m2m_dev->curr_ctx //use

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54103.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b2f0d2724ba477d326e9d654d4db1c93e98f8b93
Fixed
d346a2ef6b1ebb77d740890cfaf8478c5b286380
Fixed
d56dbfe750a8f96789cc86a911864f663e63bc5d
Fixed
715c0200b4809396998e562ce5cd0284e7314cc1
Fixed
8977d9924843823f46696d7d9432ea4b2499ed14
Fixed
2fc20f8bcc2b4d31c808a5320506c31aa2cf3834
Fixed
c677d7ae83141d390d1253abebafa49c962afb52

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54103.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.199
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.136
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.53
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.4.16
Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.5.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54103.json"