CVE-2023-5447: Use-After-Free in Service for Hardware Support App for Fingerprint Driver
Published May 11, 2024
·Updated
Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.
Affected Software
1 affected component
Synaptics Synaptics Hardware Support App
Event History
May 11, 2024
CVE Published
via MITRE·02:41 AM
Data Sourced
via MITRE·02:41 AM
DescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·02:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-5447?
CVE-2023-5447 has a medium severity rating of 5.5.
2
How do I fix CVE-2023-5447?
To fix CVE-2023-5447, update the Synaptics Hardware Support App to the latest version that mitigates the use-after-free vulnerability.
3
What is the impact of CVE-2023-5447?
CVE-2023-5447 can cause abnormal termination of the Synaptics service, leading to denial of service for users.
4
What software is affected by CVE-2023-5447?
CVE-2023-5447 affects the Synaptics Hardware Support App specifically designed for fingerprint drivers.
5
What type of vulnerability is CVE-2023-5447?
CVE-2023-5447 is classified as a use-after-free vulnerability, which can occur due to a missing lock check.