PT-2024-9251 · Linux+3 · Linux Kernel+3
Frank Li
·
Published
2024-06-20
·
Updated
2024-12-04
·
CVE-2022-48761
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 5.15.5
Description:
The vulnerability is related to the xhci-plat component in the Linux kernel, which is responsible for handling USB connections. The issue arises when the system is suspended and remote wake is enabled, causing a crash due to a synchronous external abort. This problem was hidden by the power domain driver, which called runtime resume before suspend, but a commit removed this call, making the issue happen. The vulnerability can be exploited by an attacker to cause a denial of service.
Recommendations:
To resolve the issue, update the Linux kernel to a version that includes the fix for the vulnerability, specifically the patch that calls runtime resume before suspend to ensure the clock is on before accessing the register.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse