Junglewise Threat Intelligence

CVE-2023-54026: Linux kernel OPP use-after-free in lazy_opp_tables after probe deferral

CVE-2023-54026 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Operating Performance Points (OPP) subsystem manages CPU frequency scaling and power management. A memory safety bug causes freed data structures to remain on a global list, leading to crashes when the system later attempts to access these freed objects. This can cause unexpected kernel panics and system instability during device initialization.

Technical details

The vulnerability is a use-after-free (CWE-416) in the OPP core driver (drivers/opp/core.c). When dev_pm_opp_of_find_icc_paths() returns -EPROBE_DEFER during OPP table allocation, the table is freed to retry later. However, if the OPP table uses required-opps (interdependent performance points), it may have already been added to the global lazy_opp_tables list. The error path fails to remove the freed table from this list, causing a NULL pointer dereference crash when the required-opps provider is added and the code iterates over the list. The fix calls _of_clear_opp_table() to properly remove the table from the list and adds missing mutex_destroy() calls in the error path. No authentication or special privileges are required; the vulnerability occurs during normal device initialization on affected kernels.

Affected products

  • Linux Linux Kernel 6.4 and earlier versions with OPP lazy-linking support (introduced in earlier kernels)

Timeline

  • 2023-05-30: disclosed: Fix committed upstream
  • 2023-07-23: patched: Patch merged to stable kernel trees

References

Related threats