Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52840

19
FAUCET Score

CVE-2023-52840 is a use-after-free vulnerability in the Linux kernel's Synaptics RMI4 input driver, specifically within the rmi_unregister_function() function. This flaw allows a local attacker to achieve high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (High), it has a low attack complexity and requires low privileges to exploit. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.18, < 4.19.299CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.261CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.201CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.139CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.63CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 48th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: kernel-0:5.14.0-427.70.1.el9_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-52840Low

kernel: Input: synaptics-rmi4 - fix use after free in rmi_unregister_function()

May 21, 2024

References

git.kernel.org / stable/c/2f236d8638f5b43e0c72919a6a27fe286c32053f
Patch
git.kernel.org / stable/c/303766bb92c5c225cf40f9bbbe7e29749406e2f2
Patch
git.kernel.org / stable/c/50d12253666195a14c6cd2b81c376e2dbeedbdff
Patch
git.kernel.org / stable/c/6c71e065befb2fae8f1461559b940c04e1071bd5
Patch
git.kernel.org / stable/c/7082b1fb5321037bc11ba1cf2d7ed23c6b2b521f
Patch
git.kernel.org / stable/c/c8e639f5743cf4b01f8c65e0df075fe4d782b585
Patch
git.kernel.org / stable/c/cc56c4d17721dcb10ad4e9c9266e449be1462683
Patch
git.kernel.org / stable/c/eb988e46da2e4eae89f5337e047ce372fe33d5b1
Patch