CVE-2023-53612
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53612 affects the Linux kernel's coretemp platform driver handling. The vulnerability was identified in the hwmon subsystem, specifically related to the unconventional implementation of platform device handling in the coretemp driver (NVD).

Technical details

The vulnerability stems from error-prone logic in dynamically creating and destroying platform devices. The issue occurs because the driver assumes platformdeviceadd() will synchronously bind the driver and set drvdata before returning, which can result in a NULL dereference if drivers_autoprobe is turned off for the platform bus. Additionally, the implementation causes lockdep issues for other drivers or subsystems attempting to register a CPU hotplug notifier from a platform bus notifier (NVD).

Impact

The vulnerability affects the functionality of the coretemp driver in the Linux kernel. When exploited, it can lead to NULL pointer dereferences and potential system instability. There is also a user-visible change where /sys/bus/platform/drivers/coretemp will no longer appear, and /sys/devices/platform/coretemp.n will remain present if package n is hotplugged off (NVD).

Mitigation and workarounds

The vulnerability has been resolved by simplifying the platform device handling. The fix involves tying the platform devices to the lifetime of the module itself and directly managing the hwmon interfaces from the hotplug notifiers. While this changes some system behavior, hwmon users should continue to look for the presence of hwmon interfaces, whose behavior remains unchanged (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-53616N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesOct 04, 2025
CVE-2023-53615N/AN/A
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoYesOct 04, 2025
CVE-2023-53614N/AN/A
  • Linux KernelLinux Kernel
  • kernel-abi-stablelists
NoYesOct 04, 2025
CVE-2023-53613N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-modules-extra
NoYesOct 04, 2025
CVE-2023-53612N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoYesOct 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management