SB2025121076 - Use-after-free in Linux kernel mtd ubi driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2023-53800)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ubi_resize_volume() function in drivers/mtd/ubi/vmt.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/35f8d4064e54c18424db2997059d4c0b1d13d093
- https://git.kernel.org/stable/c/3d6378f7056ac7350338f941001162a8f660853c
- https://git.kernel.org/stable/c/53818746e549e61841428892a8d94344494be797
- https://git.kernel.org/stable/c/9af31d6ec1a4be4caab2550096c6bd2ba8fba472
- https://git.kernel.org/stable/c/9c8be1f165baee53b5a36ea0b3c9281d403a1d0b
- https://git.kernel.org/stable/c/b0c951742348d216f094d16ed4f70ae73db881c0
- https://git.kernel.org/stable/c/bf795ebbb9995e2fe7945de71177f01c2f1215dc
- https://git.kernel.org/stable/c/bf9875aa7f7d624a8c084425b14bf7e5907ebc30
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.308