{"id":"DEBIAN-CVE-2023-52907","details":"In the Linux kernel, the following vulnerability has been resolved:  nfc: pn533: Wait for out_urb's completion in pn533_usb_send_frame()  Fix a use-after-free that occurs in hcd when in_urb sent from pn533_usb_send_frame() is completed earlier than out_urb. Its callback frees the skb data in pn533_send_async_complete() that is used as a transfer buffer of out_urb. Wait before sending in_urb until the callback of out_urb is called. To modify the callback of out_urb alone, separate the complete function of out_urb and ack_urb.  Found by a modified version of syzkaller.  BUG: KASAN: use-after-free in dummy_timer Call Trace:  memcpy (mm/kasan/shadow.c:65)  dummy_perform_transfer (drivers/usb/gadget/udc/dummy_hcd.c:1352)  transfer (drivers/usb/gadget/udc/dummy_hcd.c:1453)  dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:1972)  arch_static_branch (arch/x86/include/asm/jump_label.h:27)  static_key_false (include/linux/jump_label.h:207)  timer_expire_exit (include/trace/events/timer.h:127)  call_timer_fn (kernel/time/timer.c:1475)  expire_timers (kernel/time/timer.c:1519)  __run_timers (kernel/time/timer.c:1790)  run_timer_softirq (kernel/time/timer.c:1803)","modified":"2026-09-15T09:03:02.439611691Z","published":"2024-08-21T07:15:06.733Z","upstream":["CVE-2023-52907"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-52907"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52907.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52907.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52907.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}