{"schema_version":"1.9.0","id":"CVE-2023-53388","published":"2025-09-18T13:33:31.385Z","modified":"2026-08-12T03:51:38.766522196Z","related":["SUSE-SU-2025:03615-1","SUSE-SU-2025:03628-1","SUSE-SU-2025:3716-1","SUSE-SU-2025:3761-1"],"summary":"drm/mediatek: Clean dangling pointer on bind error path","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: Clean dangling pointer on bind error path\n\nmtk_drm_bind() can fail, in which case drm_dev_put() is called,\ndestroying the drm_device object. However a pointer to it was still\nbeing held in the private object, and that pointer would be passed along\nto DRM in mtk_drm_sys_prepare() if a suspend were triggered at that\npoint, resulting in a panic. Clean the pointer when destroying the\nobject in the error path to prevent this from happening.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"119f5173628aa7a0c3cf9db83460d40709e8241d"},{"fixed":"9a48f99aa7bea15e0b1d8b0040c46b4792eddf3b"},{"fixed":"a161f1d92aabb3b8463f752bdc3474dc3a5ec0e5"},{"fixed":"6a89ddee1686a8872384aaa9f0bcfa6b675acd86"},{"fixed":"49cf87919daeeeeeb9e924c39bdd9203af434461"},{"fixed":"7b551a501fa714890e55bae73efede1185728d72"},{"fixed":"f3887c771576c5d740c5c5b8bf654a8ab8020b7d"},{"fixed":"36aa8c61af55675ed967900fbe5deb32d776f051"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53388.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.7.0"},{"fixed":"4.19.276"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.235"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.173"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.99"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.16"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.2.3"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53388.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/36aa8c61af55675ed967900fbe5deb32d776f051"},{"type":"WEB","url":"https://git.kernel.org/stable/c/49cf87919daeeeeeb9e924c39bdd9203af434461"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6a89ddee1686a8872384aaa9f0bcfa6b675acd86"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7b551a501fa714890e55bae73efede1185728d72"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a48f99aa7bea15e0b1d8b0040c46b4792eddf3b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a161f1d92aabb3b8463f752bdc3474dc3a5ec0e5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f3887c771576c5d740c5c5b8bf654a8ab8020b7d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53388.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53388"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53388.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}