Executive brief
The Linux kernel's EXC3000 touchscreen input driver failed to properly stop its internal timer when the driver was shut down or during probe failures. This could allow the timer to continue running after driver resources were freed, resulting in kernel crashes and system instability when the stale timer fires.
Technical details
The vulnerability is a use-after-free (UAF) condition in the exc3000 touchscreen driver (drivers/input/touchscreen/exc3000.c). The driver schedules an internal timer but did not stop it on unbind or probe failure, leaving it running after the driver's data structures were freed. When the timer subsequently fired, it would dereference freed memory, causing a kernel panic (Oops) or crash. The fix adds a devm-managed timer shutdown action registered during probe that ensures del_timer_sync() (or timer_shutdown_sync() in later kernels) is called during driver unbind or probe error paths. The root cause stems from missing cleanup in error handling; the vulnerable code was introduced with commit 7e577a17f2ee. The fix is available in the Linux kernel stable tree.
Affected products
- Linux Linux Kernel all versions prior to patch (commit 79c81d137d36f9635bbcbc3916c0cccb418a61dd)
Timeline
- 2023-02-03: disclosed: Upstream commit 79c81d137d36f9635bbcbc3916c0cccb418a61dd
- 2023-02-03: patched: Fix committed to mainline; backported to stable kernels
- 2025-10-07: advisory: Published as CVE-2023-53651