VYPR
Medium severity4.7NVD Advisory· Published Sep 16, 2025· Updated Jun 17, 2026

CVE-2023-53310

CVE-2023-53310

Description

In the Linux kernel, the following vulnerability has been resolved:

power: supply: axp288_fuel_gauge: Fix external_power_changed race

fuel_gauge_external_power_changed() dereferences info->bat, which gets sets in axp288_fuel_gauge_probe() like this:

info->bat = devm_power_supply_register(dev, &fuel_gauge_desc, &psy_cfg);

As soon as devm_power_supply_register() has called device_add() the external_power_changed callback can get called. So there is a window where fuel_gauge_external_power_changed() may get called while info->bat has not been set yet leading to a NULL pointer dereference.

Fixing this is easy. The external_power_changed callback gets passed the power_supply which will eventually get stored in info->bat, so fuel_gauge_external_power_changed() can simply directly use the passed in psy argument which is always valid.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Linux/Kernel6 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.18,<6.1.31
    • cpe:2.3:o:linux:linux_kernel:6.4:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.4:rc3:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 5.18
  • osv-coords
    Range: >= 5.18.0, < 6.1.31

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.