Executive brief
The Linux kernel's HID multitouch driver incorrectly manages memory for input device names, causing a use-after-free vulnerability. When a touchscreen or similar multitouch device is unregistered, the kernel fires an event that depends on a name string that has already been freed, potentially allowing an attacker with local access to trigger a kernel crash or execute code. This affects systems with multitouch input devices (touchscreens, touchpads, tablets).
Technical details
The vulnerability is a use-after-free flaw in the HID multitouch driver (drivers/hid/hid-multitouch.c). The vulnerable code allocated memory for the input device name using devm_kzalloc with the input device (input_dev) as the reference, rather than the HID device. When the input device is unregistered and subsequently generates a uevent that references the name, the devres manager frees the memory under the input device context before the uevent is fully processed. An attacker with local access can trigger device add/removal to cause a kernel use-after-free condition. The fix changes the devm allocation context to reference the HID device instead and uses devm_kasprintf for cleaner memory management. Patch commits: 15ec7cb55e7d88755aa01d44a7a1015a42bfce86, 1d7833db9fd118415dace2ca157bfa603dec9c8c.
Affected products
- Linux Linux kernel 2.6.11 through 6.x (affected kernel versions with HID multitouch driver; patch committed August 2023)
Timeline
- 2023-08-24: disclosed: Vulnerability reported and fix authored by Rahul Rameshbabu
- 2023-09-13: patched: Patch merged into stable kernel branches
- 2023-09-19: patched: Additional stable branches patched
- 2025-10-01: other: CVE-2023-53454 published