Bug 2405725 (CVE-2023-53704) - CVE-2023-53704 kernel: clk: imx: clk-imx8mp: improve error handling in imx8mp_clocks_probe()
Summary: CVE-2023-53704 kernel: clk: imx: clk-imx8mp: improve error handling in imx8mp...
Keywords:
Status: NEW
Alias: CVE-2023-53704
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-22 14:02 UTC by OSIDB Bzimport
Modified: 2026-06-29 18:26 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-10-22 14:02:27 UTC
In the Linux kernel, the following vulnerability has been resolved:

clk: imx: clk-imx8mp: improve error handling in imx8mp_clocks_probe()

Replace of_iomap() and kzalloc() with devm_of_iomap() and devm_kzalloc()
which can automatically release the related memory when the device
or driver is removed or unloaded to avoid potential memory leak.

In this case, iounmap(anatop_base) in line 427,433 are removed
as manual release is not required.

Besides, referring to clk-imx8mq.c, check the return code of
of_clk_add_hw_provider, if it returns negtive, print error info
and unregister hws, which makes the program more robust.

Comment 1 Jon Moroney 2025-10-22 18:01:56 UTC Comment hidden (spam)

Note You need to log in before you can comment on or make changes to this bug.