LiveActive security incident?Get immediate response
CVE Record

CVE-2023-53651: Input: exc3000 - properly stop timer on shutdown

In the Linux kernel, the following vulnerability has been resolved: Input: exc3000 - properly stop timer on shutdown We need to stop the timer on driver unbind or probe failures, otherwise we get UAF/Oops.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue is in the exc3000 input driver. If the driver is removed or fails during setup, a timer may continue running and later access freed memory, causing a kernel crash or related instability.

Executive priority

Treat as a targeted kernel stability risk, not a confirmed widespread emergency. Prioritize patching where touch-enabled Linux or embedded devices use this driver, and rely on vendor kernel packages for remediation.

Technical view

The source describes a use-after-free/Oops condition caused by not stopping the exc3000 driver timer during unbind or probe failure. Stable kernel commit references are provided, but the bundle does not include CVSS, CWE, exploitability detail, or distro-specific fixed package versions.

Likely exposure

Exposure is likely limited to Linux systems that use or load the exc3000 touchscreen/input driver, especially embedded or touch-enabled devices. Downstream vendor kernels may differ because fixes can be backported.

Exploitation context

No CISA KEV listing is present, and the supplied sources do not claim active exploitation. The described failure path involves driver shutdown or probe failure, not a documented remote attack path.

Researcher notes

The affected version data in the bundle is sparse and commit-oriented. Validate against upstream stable commits and downstream backports before declaring exposure. The available description supports UAF/Oops impact, but not exploit primitives or privilege requirements.

Mitigation direction

  • Update to a kernel release or vendor package containing the referenced stable fixes.
  • Prioritize systems using EXC3000 touchscreen/input hardware or loading the exc3000 driver.
  • If updates are unavailable, check vendor guidance for disabling or avoiding the affected driver.
  • Track Linux distribution advisories for backported fixed kernel package names.

Validation and detection

  • Inventory Linux hosts and embedded devices for exc3000 driver usage.
  • Compare running kernel builds against vendor advisories and referenced stable commits.
  • Review kernel logs for exc3000 probe, unbind, Oops, or crash evidence.
  • Confirm patched systems no longer use affected downstream kernel builds.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-53651 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
4Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux7e577a17f2eefeef32f1106ebf91e7cd143ba654, 7e577a17f2eefeef32f1106ebf91e7cd143ba654, 7e577a17f2eefeef32f1106ebf91e7cd143ba654unaffected
LinuxLinux4.15, 0, 6.1.20, 6.2.3, 6.3affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.