PT-2025-38371 · Linux+3 · Linux Kernel+3
CVE-2023-53392
·
Publicado
2023-11-07
·
Atualizado
2025-09-29
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.16
Description
The Linux kernel contained a flaw where a kernel panic could occur during a warm reset. This occurred because the
device->fw client was set to NULL during a warm reset. If a bus driver was registered after this NULL setting and before new firmware clients were enumerated, a kernel panic resulted in the ishtp cl bus match() function due to a reference to device->fw client->props.protocol name. The issue was exposed after a change in kernel version 5.16 that loaded bus drivers only for matching devices, specifically with the cros ec ishtp device and driver.Recommendations
Update to kernel version 5.16 or later to resolve this issue.
Exploit
Correção
DoS
Exposure of Resource to Wrong Sphere
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astra Linux
Centos
Linux Kernel
Red Hat