In the Linux kernel, the following vulnerability has been resolved:
usb: typec: altmodes/displayport: fix pinassignmentshow
This patch fixes negative indexing of buf array in pinassignmentshow when getcurrentpin_assignments returns 0 i.e. no compatible pin assignments are found.
BUG: KASAN: use-after-free in pinassignmentshow+0x26c/0x33c ... Call trace: dumpbacktrace+0x110/0x204 dumpstacklvl+0x84/0xbc printreport+0x358/0x974 kasanreport+0x9c/0xfc _dokernelfault+0xd4/0x2d4 dobadarea+0x48/0x168 dotagcheckfault+0x24/0x38 domemabort+0x6c/0x14c el1abort+0x44/0x68 el1h64synchandler+0x64/0xa4 el1h64sync+0x78/0x7c pinassignmentshow+0x26c/0x33c devattr_show+0x50/0xc0
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54186.json",
"cna_assigner": "Linux"
}