cbcvebase.
CVE-2023-52882
published 2024-05-30

CVE-2023-52882: In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change While PLL CPUX clock rate…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: h6: Reparent CPUX during PLL CPUX rate change While PLL CPUX clock rate change when CPU is running from it works in vast majority of cases, now and then it causes instability. This leads to system crashes and other undefined behaviour. After a lot of testing (30+ hours) while also doing a lot of frequency switches, we can't observe any instability issues anymore when doing reparenting to stable clock like 24 MHz oscillator.

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < fe11826ffa200e1a7a826e745163cb2f47875f66fe11826ffa200e1a7a826e745163cb2f47875f66
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < bfc78b4628497eb6df09a6b5bba9dd31616ee175bfc78b4628497eb6df09a6b5bba9dd31616ee175
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < f1fa9a9816204ac4b118b2e613d3a7c981355019f1fa9a9816204ac4b118b2e613d3a7c981355019
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < 70f64cb29014e4c4f1fabd3265feebd80590d06970f64cb29014e4c4f1fabd3265feebd80590d069
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < 0b82eb134d2942ecc669e2ab2be3f0a58d79428a0b82eb134d2942ecc669e2ab2be3f0a58d79428a
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < 9708e5081cfc4f085690294163389bcf82655f909708e5081cfc4f085690294163389bcf82655f90
linuxlinux>= 524353ea480b0094c16f2b5684ce7e0a23ab3685 < 7e91ed763dc07437777bd012af7a2bd4493731ff7e91ed763dc07437777bd012af7a2bd4493731ff
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 4.17 < 5.4.2765.4.276
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 5.5 < 5.10.2175.10.217
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.