cbcvebase.
CVE-2023-52457
published 2024-02-23

CVE-2023-52457: In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed…

PriorityP335high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from .remove() makes the driver core emit the little helpful error message: remove callback returned a non-zero value. This will be ignored. and then remove the device anyhow. So all resources that were not freed are leaked in this case. Skipping serial8250_unregister_port() has the potential to keep enough of the UART around to trigger a use-after-free. So replace the error return (and with it the little helpful error message) by a more useful error message and continue to cleanup.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2d66412563ef8953e2bac2d98d2d832b3f3f49cd < b502fb43f7fb55aaf07f6092ab44657595214b93b502fb43f7fb55aaf07f6092ab44657595214b93
linuxlinux>= 5.10.156 < 5.10.2095.10.209
linuxlinux>= 5.15.80 < 5.15.1485.15.148
linuxlinux>= 5.4.225 < 5.4.2685.4.268
linuxlinux>= 6.0.10 < 6.16.1
linuxlinux>= d833cba201adf9237168e19f0d76e4d7aa69f303 < bc57f3ef8a9eb0180606696f586a6dcfaa175ed0bc57f3ef8a9eb0180606696f586a6dcfaa175ed0
linuxlinux>= e0db709a58bdeb8966890882261a3f8438c5c9b7 < 828cd829483f0cda920710997aed79130b0af690828cd829483f0cda920710997aed79130b0af690
linuxlinux>= e3f0c638f428fd66b5871154b62706772045f91a < d74173bda29aba58f822175d983d07c8ed335494d74173bda29aba58f822175d983d07c8ed335494
linuxlinux>= e3f0c638f428fd66b5871154b62706772045f91a < 887a558d0298d36297daea039954c39940228d9b887a558d0298d36297daea039954c39940228d9b
linuxlinux>= e3f0c638f428fd66b5871154b62706772045f91a < 95e4e0031effad9837af557ecbfd4294a4d8aeee95e4e0031effad9837af557ecbfd4294a4d8aeee
linuxlinux>= e3f0c638f428fd66b5871154b62706772045f91a < ad90d0358bd3b4554f243a425168fc7cebe7d04ead90d0358bd3b4554f243a425168fc7cebe7d04e
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-176.1965.4.0-176.196
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 5.10.156 < 5.10.2095.10.209
linuxlinux_kernel>= 5.15.80 < 5.15.1485.15.148
linuxlinux_kernel>= 5.4.225 < 5.4.2685.4.268
linuxlinux_kernel>= 6.0.10 < 6.1.756.1.75
linuxlinux_kernel>= 6.2 < 6.6.146.6.14

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.