Junglewise Threat Intelligence

CVE-2023-54186: Linux kernel USB TypeC DisplayPort use-after-free in pin_assignment_show

CVE-2023-54186 · Severity: high · CVSS 7.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's USB Type-C DisplayPort alternate mode driver contains a use-after-free vulnerability in the pin_assignment_show function. When no compatible pin assignments are found, the code attempts to access a buffer at an invalid negative index, potentially allowing a local attacker to read kernel memory or crash the system.

Technical details

The vulnerability is a use-after-free and out-of-bounds buffer access in the pin_assignment_show() sysfs attribute handler in drivers/usb/typec/altmodes/displayport.c. When get_current_pin_assignments() returns 0 (indicating no compatible pin assignments), the code proceeds to write a newline to buf[len - 1], which evaluates to buf[-1], accessing memory outside the allocated buffer. This is a classic negative indexing vulnerability triggered by insufficient input validation. The attack requires local access to the sysfs interface, making it a local privilege escalation or information disclosure vector. A fix was merged upstream commit d8f28269dd4bf9b55c3fb376ae31512730a96fce, adding a bounds check: if (len == 0) len++; before the buffer write.

Affected products

  • Linux Linux Kernel 5.0 through 6.3 (affected versions vary by distribution; patch applied May 2023)

Timeline

  • 2025-12-30: disclosed: Advisory published on NVD
  • 2023-05-08: patched: Upstream patch commit d8f28269dd4bf9b55c3fb376ae31512730a96fce authored and applied to stable branches

References

Related threats