{"id":"DEBIAN-CVE-2023-53106","details":"In the Linux kernel, the following vulnerability has been resolved:  nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition  This bug influences both st_nci_i2c_remove and st_nci_spi_remove. Take st_nci_i2c_remove as an example.  In st_nci_i2c_probe, it called ndlc_probe and bound &ndlc-\u003esm_work with llt_ndlc_sm_work.  When it calls ndlc_recv or timeout handler, it will finally call schedule_work to start the work.  When we call st_nci_i2c_remove to remove the driver, there may be a sequence as follows:  Fix it by finishing the work before cleanup in ndlc_remove  CPU0                  CPU1                      |llt_ndlc_sm_work st_nci_i2c_remove   |   ndlc_remove       |      st_nci_remove  |      nci_free_device|      kfree(ndev)    | //free ndlc-\u003endev   |                     |llt_ndlc_rcv_queue                     |nci_recv_frame                     |//use ndlc-\u003endev","modified":"2026-09-15T09:02:50.076731116Z","published":"2025-05-02T16:15:29.520Z","upstream":["CVE-2023-53106"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53106"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53106.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53106.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.25-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53106.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}