CVE-2023-52645
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then…
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with genpd and *after that* the driver attempts to power them on in the probe sequence, then it is possible that a race condition occurs if genpd tries to power them on in the same time. The same is valid for powering them off before unregistering them from genpd. Attempt to fix race conditions by first removing the domains from genpd and *after that* powering down domains. Also first power up the domains and *after that* register them to genpd.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/339ddc983bc1622341d95f244c361cda3da3a4ffPatch
- https://git.kernel.org/stable/c/3cd1d92ee1dbf3e8f988767eb75f26207397792bPatch
- https://git.kernel.org/stable/c/475426ad1ae0bfdfd8f160ed9750903799392438Patch
- https://git.kernel.org/stable/c/c41336f4d69057cbf88fed47951379b384540df5Patch
- https://git.kernel.org/stable/c/f83b9abee9faa4868a6fac4669b86f4c215dae25Patch
- https://git.kernel.org/stable/c/339ddc983bc1622341d95f244c361cda3da3a4ffPatch
- https://git.kernel.org/stable/c/3cd1d92ee1dbf3e8f988767eb75f26207397792bPatch
- https://git.kernel.org/stable/c/475426ad1ae0bfdfd8f160ed9750903799392438Patch
- https://git.kernel.org/stable/c/c41336f4d69057cbf88fed47951379b384540df5Patch
- https://git.kernel.org/stable/c/f83b9abee9faa4868a6fac4669b86f4c215dae25Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.