cbcvebase.
CVE-2023-52498
published 2024-03-11

CVE-2023-52498: In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Fix possible deadlocks in core system-wide PM code It is reported that in…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Fix possible deadlocks in core system-wide PM code It is reported that in low-memory situations the system-wide resume core code deadlocks, because async_schedule_dev() executes its argument function synchronously if it cannot allocate memory (and not only in that case) and that function attempts to acquire a mutex that is already held. Executing the argument function synchronously from within dpm_async_fn() may also be problematic for ordering reasons (it may cause a consumer device's resume callback to be invoked before a requisite supplier device's one, for example). Address this by changing the code in question to use async_schedule_dev_nocall() for scheduling the asynchronous execution of device suspend and resume functions and to directly run them synchronously if async_schedule_dev_nocall() returns false.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < f46eb832389f162ad13cb780d0b8cde93641990df46eb832389f162ad13cb780d0b8cde93641990d
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < a1d62c775b07213c73f81ae842424c74dd14b5f0a1d62c775b07213c73f81ae842424c74dd14b5f0
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < e1c9d32c98309ae764893a481552d3f99d46cb34e1c9d32c98309ae764893a481552d3f99d46cb34
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < e681e29d1f59a04ef773296e4bebb17b1b79f8fee681e29d1f59a04ef773296e4bebb17b1b79f8fe
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < 9bd3dce27b01c51295b60e1433e1dadfb16649f79bd3dce27b01c51295b60e1433e1dadfb16649f7
linuxlinux>= 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 < 7839d0078e0d5e6cc2fa0b0dfbee71de74f1e5577839d0078e0d5e6cc2fa0b0dfbee71de74f1e557
linuxlinux>= 4.14.171 < 4.154.15
linuxlinux>= 4.19.103 < 4.204.20
linuxlinux>= 5.4.19 < 5.55.5
linuxlinux>= 5.5.3 < 5.65.6
linuxlinux_kernel< 5.10.2105.10.210
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-202.2225.4.0-202.222
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.11 < 5.15.1495.15.149
linuxlinux_kernel>= 5.16 < 6.1.766.1.76

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.