cbcvebase.
CVE-2023-54159
published 2025-12-24

CVE-2023-54159: In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix kernel panic at qmu transfer done irq handler When handle qmu transfer irq…

PriorityP420
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix kernel panic at qmu transfer done irq handler When handle qmu transfer irq, it will unlock @mtu->lock before give back request, if another thread handle disconnect event at the same time, and try to disable ep, it may lock @mtu->lock and free qmu ring, then qmu irq hanlder may get a NULL gpd, avoid the KE by checking gpd's value before handling it. e.g. qmu done irq on cpu0 thread running on cpu1 qmu_done_tx() handle gpd [0] mtu3_requ_complete() mtu3_gadget_ep_disable() unlock @mtu->lock give back request lock @mtu->lock mtu3_ep_disable() mtu3_gpd_ring_free() unlock @mtu->lock lock @mtu->lock get next gpd [1] [1]: goto [0] to handle next gpd, and next gpd may be NULL.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < 26ca30516b2c49dd04c134cbdf122311c538df9826ca30516b2c49dd04c134cbdf122311c538df98
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < 012936502a9cb7b0604e85bb961eb15e2bb40dd9012936502a9cb7b0604e85bb961eb15e2bb40dd9
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < ee53a7a88027cea765c68f3b00a50b8f58d6f786ee53a7a88027cea765c68f3b00a50b8f58d6f786
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < f26273428657ef4ca74740e578ae45a3be492f6ff26273428657ef4ca74740e578ae45a3be492f6f
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < b636aff94a67be46582d4321d11743f1a10cc2c1b636aff94a67be46582d4321d11743f1a10cc2c1
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < 3a7d4959560a2ee493ef222e3b63d359365f41ec3a7d4959560a2ee493ef222e3b63d359365f41ec
linuxlinux>= 48e0d3735aa557a8adaf94632ca3cf78798e8505 < d28f4091ea7ec3510fd6a3c6d433234e7a2bef14d28f4091ea7ec3510fd6a3c6d433234e7a2bef14
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 5.2.0 < 5.4.2435.4.243
linuxlinux_kernel>= 5.5.0 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.