CVE-2023-54079 (GCVE-0-2023-54079)
Vulnerability from cvelistv5
Published
2025-12-24 13:06
Modified
2026-08-05 09:17
Summary
In the Linux kernel, the following vulnerability has been resolved: power: supply: bq27xxx: Fix poll_interval handling and races on remove Before this patch bq27xxx_battery_teardown() was setting poll_interval = 0 to avoid bq27xxx_battery_update() requeuing the delayed_work item. There are 2 problems with this: 1. If the driver is unbound through sysfs, rather then the module being rmmod-ed, this changes poll_interval unexpectedly 2. This is racy, after it being set poll_interval could be changed before bq27xxx_battery_update() checks it through /sys/module/bq27xxx_battery/parameters/poll_interval Fix this by added a removed attribute to struct bq27xxx_device_info and using that instead of setting poll_interval to 0. There also is another poll_interval related race on remove(), writing /sys/module/bq27xxx_battery/parameters/poll_interval will requeue the delayed_work item for all devices on the bq27xxx_battery_devices list and the device being removed was only removed from that list after cancelling the delayed_work item. Fix this by moving the removal from the bq27xxx_battery_devices list to before cancelling the delayed_work item.
Impacted products
Vendor Product Version
Linux Linux Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Version: 8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/power/supply/bq27xxx_battery.c",
            "include/linux/power/bq27xxx_battery.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4c9615474fb0a41cfad658d78db3c9ec70912969",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "465d919151a1e8d40daf366b868914f59d073211",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "0c5f4cec759679c290720fbcf6bb81768e21c95b",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "e85757da9091998276ff21a13915ac25229cc232",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "e98e5bebfcafc75a7b41192a607dfea5c1268afa",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "d952a1eaafcc5f0351caad5dbe9b5b3300d1d529",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "b12faeca0e819ea09051a705fef9df7ea7e9e18c",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            },
            {
              "lessThan": "c00bc80462afc7963f449d7f21d896d2f629cacc",
              "status": "affected",
              "version": "8cfaaa811894a3ae2d7360a15a6cfccff3ebc7db",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/power/supply/bq27xxx_battery.c",
            "include/linux/power/bq27xxx_battery.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.3"
            },
            {
              "lessThan": "3.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.14.*",
              "status": "unaffected",
              "version": "4.14.316",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.284",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.244",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.181",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.114",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.31",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.3.*",
              "status": "unaffected",
              "version": "6.3.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.14.316",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.284",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.244",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.181",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.114",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.31",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3.5",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.4",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: bq27xxx: Fix poll_interval handling and races on remove\n\nBefore this patch bq27xxx_battery_teardown() was setting poll_interval = 0\nto avoid bq27xxx_battery_update() requeuing the delayed_work item.\n\nThere are 2 problems with this:\n\n1. If the driver is unbound through sysfs, rather then the module being\n   rmmod-ed, this changes poll_interval unexpectedly\n\n2. This is racy, after it being set poll_interval could be changed\n   before bq27xxx_battery_update() checks it through\n   /sys/module/bq27xxx_battery/parameters/poll_interval\n\nFix this by added a removed attribute to struct bq27xxx_device_info and\nusing that instead of setting poll_interval to 0.\n\nThere also is another poll_interval related race on remove(), writing\n/sys/module/bq27xxx_battery/parameters/poll_interval will requeue\nthe delayed_work item for all devices on the bq27xxx_battery_devices\nlist and the device being removed was only removed from that list\nafter cancelling the delayed_work item.\n\nFix this by moving the removal from the bq27xxx_battery_devices list\nto before cancelling the delayed_work item."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Both sides of the race are reached through local interfaces \u2014 the `poll_interval` module parameter under /sys/module/, driver bind/unbind (or rmmod), and world-readable power_supply attributes under /sys/class/power_supply/. No network or physical access is required.\nAC:L - The attacker drives both sides of the race and can retry indefinitely (unbind/bind loop plus a writer/reader loop on the sysfs attributes), and the widest window spans the entire `power_supply_unregister()` call, which takes milliseconds. Once the work is re-armed the freed object is not touched for up to `poll_interval` seconds, leaving a large window for reliable heap reclaim.\nPR:L - The re-queue leg of the race is reachable from an ordinary unprivileged local user: reading world-readable /sys/class/power_supply/bq27xxx-N/capacity (and friends) enters `bq27xxx_battery_get_property()` \u2192 `bq27xxx_battery_update_unlocked()` \u2192 `mod_delayed_work()`, which is precisely the path the fix\u0027s `di-\u003eremoved` flag closes under `di-\u003elock`. The removal itself is a routine environmental event (module unload, sysfs unbind, or hot-removal of a w1/HDQ battery pack) rather than a privilege the attacker must hold.\nUI:N - No victim action is required \u2014 the attacker\u0027s own loops on the sysfs interfaces trigger the race, and the removal path also occurs during ordinary system operation such as module unload or battery hot-removal.\nS:U - The use-after-free is confined to kernel memory within the same security authority; there is no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - The resurrected work item reads `di-\u003eregs` and `di-\u003ebat` as raw pointers out of freed slab memory and dereferences them, so an attacker who reclaims the ~200-byte object gains an arbitrary kernel-memory read primitive whose results are observable through the power_supply cache.\nI:H - The freed object is dereferenced for an indirect call, `di-\u003ebus.read(di, ...)`, and the freed memory also hosts the armed `timer_list`/`work_struct` \u2014 both give control-flow hijack from attacker-sprayed data, and `mutex_lock(\u0026di-\u003elock)` plus `di-\u003ecache = cache` write into the freed allocation.\nA:H - Even without successful reclaim, running a delayed work item whose `work_struct` and mutex live in freed memory reliably produces workqueue/timer list corruption and a kernel oops \u2014 the original OOPS this code path was supposed to prevent."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:17:02.722Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4c9615474fb0a41cfad658d78db3c9ec70912969"
        },
        {
          "url": "https://git.kernel.org/stable/c/465d919151a1e8d40daf366b868914f59d073211"
        },
        {
          "url": "https://git.kernel.org/stable/c/0c5f4cec759679c290720fbcf6bb81768e21c95b"
        },
        {
          "url": "https://git.kernel.org/stable/c/e85757da9091998276ff21a13915ac25229cc232"
        },
        {
          "url": "https://git.kernel.org/stable/c/e98e5bebfcafc75a7b41192a607dfea5c1268afa"
        },
        {
          "url": "https://git.kernel.org/stable/c/d952a1eaafcc5f0351caad5dbe9b5b3300d1d529"
        },
        {
          "url": "https://git.kernel.org/stable/c/b12faeca0e819ea09051a705fef9df7ea7e9e18c"
        },
        {
          "url": "https://git.kernel.org/stable/c/c00bc80462afc7963f449d7f21d896d2f629cacc"
        }
      ],
      "title": "power: supply: bq27xxx: Fix poll_interval handling and races on remove",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-54079",
    "datePublished": "2025-12-24T13:06:11.956Z",
    "dateReserved": "2025-12-24T13:02:52.514Z",
    "dateUpdated": "2026-08-05T09:17:02.722Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…