{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-53866",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-12-09T01:27:17.829Z",
        "datePublished": "2025-12-09T01:30:35.817Z",
        "dateUpdated": "2026-08-05T09:16:27.597Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:16:27.597Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: soc-compress: Reposition and add pcm_mutex\n\nIf panic_on_warn is set and compress stream(DPCM) is started,\nthen kernel panic occurred because card->pcm_mutex isn't held appropriately.\nIn the following functions, warning were issued at this line\n\"snd_soc_dpcm_mutex_assert_held\".\n\nstatic int dpcm_be_connect(struct snd_soc_pcm_runtime *fe,\n\t\tstruct snd_soc_pcm_runtime *be, int stream)\n{\n\t...\n\tsnd_soc_dpcm_mutex_assert_held(fe);\n\t...\n}\n\nvoid dpcm_be_disconnect(struct snd_soc_pcm_runtime *fe, int stream)\n{\n\t...\n\tsnd_soc_dpcm_mutex_assert_held(fe);\n\t...\n}\n\nvoid snd_soc_runtime_action(struct snd_soc_pcm_runtime *rtd,\n\t\t\t    int stream, int action)\n{\n\t...\n\tsnd_soc_dpcm_mutex_assert_held(rtd);\n\t...\n}\n\nint dpcm_dapm_stream_event(struct snd_soc_pcm_runtime *fe, int dir,\n\tint event)\n{\n\t...\n\tsnd_soc_dpcm_mutex_assert_held(fe);\n\t...\n}\n\nThese functions are called by soc_compr_set_params_fe, soc_compr_open_fe\nand soc_compr_free_fe\nwithout pcm_mutex locking. And this is call stack.\n\n[  414.527841][ T2179] pc : dpcm_process_paths+0x5a4/0x750\n[  414.527848][ T2179] lr : dpcm_process_paths+0x37c/0x750\n[  414.527945][ T2179] Call trace:\n[  414.527949][ T2179]  dpcm_process_paths+0x5a4/0x750\n[  414.527955][ T2179]  soc_compr_open_fe+0xb0/0x2cc\n[  414.527972][ T2179]  snd_compr_open+0x180/0x248\n[  414.527981][ T2179]  snd_open+0x15c/0x194\n[  414.528003][ T2179]  chrdev_open+0x1b0/0x220\n[  414.528023][ T2179]  do_dentry_open+0x30c/0x594\n[  414.528045][ T2179]  vfs_open+0x34/0x44\n[  414.528053][ T2179]  path_openat+0x914/0xb08\n[  414.528062][ T2179]  do_filp_open+0xc0/0x170\n[  414.528068][ T2179]  do_sys_openat2+0x94/0x18c\n[  414.528076][ T2179]  __arm64_sys_openat+0x78/0xa4\n[  414.528084][ T2179]  invoke_syscall+0x48/0x10c\n[  414.528094][ T2179]  el0_svc_common+0xbc/0x104\n[  414.528099][ T2179]  do_el0_svc+0x34/0xd8\n[  414.528103][ T2179]  el0_svc+0x34/0xc4\n[  414.528125][ T2179]  el0t_64_sync_handler+0x8c/0xfc\n[  414.528133][ T2179]  el0t_64_sync+0x1a0/0x1a4\n[  414.528142][ T2179] Kernel panic - not syncing: panic_on_warn set ...\n\nSo, I reposition and add pcm_mutex to resolve lockdep error."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code is reached only through local device nodes — `open()`/`close()`/`SNDRV_COMPRESS_SET_PARAMS` on `/dev/snd/comprC#D#` and `SNDRV_CTL_IOCTL_ELEM_WRITE` on `/dev/snd/controlC#`. There is no network-facing path into the ASoC DPCM layer.\nAC:L - The attacker drives both sides of the race itself — one thread opening/closing the compress stream (`card->mutex` only) and another writing a DAPM mixer/mux control to enter `snd_soc_dpcm_runtime_update()` (`pcm_mutex` only) — with no shared lock and unlimited retries. On `panic_on_warn` kernels a single `open()` of the compress device is deterministically fatal.\nPR:L - An ordinary local account with access to the ALSA device nodes is sufficient; the desktop session user gets these via udev ACLs or the `audio` group, and media processes hold them on Android. No capability, root, or namespace trick is needed.\nUI:N - The attacker opens the compress device and writes the kcontrol from its own processes. No victim action or pre-existing audio session is required.\nS:U - The corruption is confined to kernel heap objects (`struct snd_soc_dpcm`) managed by the same kernel security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - Unlocked traversal of `be_clients` in `dpcm_dapm_stream_event()` and `dpcm_prune_paths()` reads `snd_soc_dpcm` nodes concurrently freed by `dpcm_be_disconnect()`, and dereferences the stale `dpcm->be` pointer; with heap grooming the reclaimed slab contents become attacker-readable, and the lockdep splat additionally leaks kernel addresses.\nI:H - The same unsynchronized walks write through freed/stale pointers (`dpcm->state = SND_SOC_DPCM_LINK_STATE_FREE`, `dpcm_set_be_update_state(dpcm->be, …)`), and the `fe_clients` list is mutated by two FEs under different spinlocks, giving list-corruption and use-after-free write primitives usable for control-flow hijack.\nA:H - The originally reported effect is an outright kernel panic (`lockdep_assert_held` WARN with `panic_on_warn`), and the underlying use-after-free/list corruption produces oopses and slab-corruption BUGs on ordinary configurations."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "sound/soc/soc-compress.c"
                    ],
                    "versions": [
                        {
                            "version": "b7898396f4bbe160f546d0c5e9fa17cca9a7d153",
                            "lessThan": "9a9942cbdb7c3f41452f7bc4a9ff9f0b45eb3651",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b7898396f4bbe160f546d0c5e9fa17cca9a7d153",
                            "lessThan": "37a3eb6054d17676ce2a0bb5dd1fbf7733ecfa7d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b7898396f4bbe160f546d0c5e9fa17cca9a7d153",
                            "lessThan": "aa9ff6a4955fdba02b54fbc4386db876603703b7",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "sound/soc/soc-compress.c"
                    ],
                    "versions": [
                        {
                            "version": "5.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.16",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.2.3",
                            "lessThanOrEqual": "6.2.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.3",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.1.16"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.2.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17",
                                    "versionEndExcluding": "6.3"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/9a9942cbdb7c3f41452f7bc4a9ff9f0b45eb3651"
                },
                {
                    "url": "https://git.kernel.org/stable/c/37a3eb6054d17676ce2a0bb5dd1fbf7733ecfa7d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/aa9ff6a4955fdba02b54fbc4386db876603703b7"
                }
            ],
            "title": "ASoC: soc-compress: Reposition and add pcm_mutex",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}