PT-2025-37540 · Linux+3 · Linux Kernel+3
Published
2023-04-18
·
Updated
2026-04-14
·
CVE-2023-53176
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel related to serial port handling. Specifically, when unbinding a serial port hardware-specific 8250 driver, the generic serial8250 driver takes over the port. This can lead to an attempt to call functions from the previously unbound driver, resulting in an error. This issue can cause an imprecise external abort and potentially lead to system instability. The root cause is the continued use of the port-specific driver's power management (
port->pm) after the driver is unbound, and the subsequent attempt by serial8250 pm() to call it.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse