drivers: base: Free devm resources when unregistering a device
Summary
| CVE | CVE-2023-53596 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-04 16:15:56 UTC |
| Updated | 2026-06-18 14:30:05 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: drivers: base: Free devm resources when unregistering a device In the current code, devres_release_all() only gets called if the device has a bus and has been probed. This leads to issues when using bus-less or driver-less devices where the device might never get freed if a managed resource holds a reference to the device. This is happening in the DRM framework for example. We should thus call devres_release_all() in the device_del() function to make sure that the device-managed actions are properly executed when the device is unregistered, even if it has neither a bus nor a driver. This is effectively the same change than commit 2f8d16a996da ("devres: release resources on device_del()") that got reverted by commit a525a3ddeaca ("driver core: free devres in device_release") over memory leaks concerns. This patch effectively combines the two commits mentioned above to release the resources both on device_del() and device_release() and get the best of both worlds. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-415
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc 83e2ec36a92432e9445e853c12becbbae353b511 git | Not specified |
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc b9ef4b0aa91d2f9f5951faafdbbd47cf01799ec3 git | Not specified |
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc 297992e5c63528e603666e36081836204fc36ec9 git | Not specified |
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc 3bcc4c2a096e8342c8c719e595ce15de212694dd git | Not specified |
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc c8c426fae26086a0ca8ab6cc6da2de79810ec038 git | Not specified |
| CNA | Linux | Linux | affected a525a3ddeaca69f405d98442ab3c0746e53168dc 699fb50d99039a50e7494de644f96c889279aca3 git | Not specified |
| CNA | Linux | Linux | affected 3.7 | Not specified |
| CNA | Linux | Linux | unaffected 3.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.258 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.53 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.4.16 6.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.5.3 6.5.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/699fb50d99039a50e7494de644f96c889279aca3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/83e2ec36a92432e9445e853c12becbbae353b511 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/3bcc4c2a096e8342c8c719e595ce15de212694dd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/297992e5c63528e603666e36081836204fc36ec9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/c8c426fae26086a0ca8ab6cc6da2de79810ec038 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/b9ef4b0aa91d2f9f5951faafdbbd47cf01799ec3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.