cbcvebase.
CVE-2023-52749
published 2024-05-21

CVE-2023-52749: In the Linux kernel, the following vulnerability has been resolved: spi: Fix null dereference on suspend A race condition exists where a synchronous (noqueue)…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: Fix null dereference on suspend A race condition exists where a synchronous (noqueue) transfer can be active during a system suspend. This can cause a null pointer dereference exception to occur when the system resumes. Example order of events leading to the exception: 1. spi_sync() calls __spi_transfer_message_noqueue() which sets ctlr->cur_msg 2. Spi transfer begins via spi_transfer_one_message() 3. System is suspended interrupting the transfer context 4. System is resumed 6. spi_controller_resume() calls spi_start_queue() which resets cur_msg to NULL 7. Spi transfer context resumes and spi_finalize_current_message() is called which dereferences cur_msg (which is now NULL) Wait for synchronous transfers to complete before suspending by acquiring the bus mutex and setting/checking a suspend flag.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.66-1 (bookworm)linux 6.1.66-1 (bookworm)
linuxlinux
linuxlinux>= ae7d2346dc89ae89a6e0aabe6037591a11e593c0 < 4ec4508db97502a12daee88c74782e8d35ced0684ec4508db97502a12daee88c74782e8d35ced068
linuxlinux>= ae7d2346dc89ae89a6e0aabe6037591a11e593c0 < 96474ea47dc67b0704392d59192b233c8197db0e96474ea47dc67b0704392d59192b233c8197db0e
linuxlinux>= ae7d2346dc89ae89a6e0aabe6037591a11e593c0 < bef4a48f4ef798c4feddf045d49e53c8a97d5e37bef4a48f4ef798c4feddf045d49e53c8a97d5e37
linuxlinux_kernel< 6.1.666.1.66
linuxlinux_kernel>= 0 < 6.1.66-16.1.66-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 6.2 < 6.6.36.6.3
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.