Lucene search

K
osvGoogleOSV:CVE-2023-52749
HistoryMay 21, 2024 - 4:15 p.m.

CVE-2023-52749

2024-05-2116:15:00
Google
osv.dev
4
linux kernel
vulnerability fix
null dereference
system suspend
race condition
spi control
synchronous transfer
system resume

AI Score

6.7

Confidence

Low

In the Linux kernel, the following vulnerability has been resolved: spi: Fix null dereference on suspend A race condition exists where a synchronous (noqueue) transfer can be active during a system suspend. This can cause a null pointer dereference exception to occur when the system resumes. Example order of events leading to the exception: 1. spi_sync() calls __spi_transfer_message_noqueue() which sets ctlr->cur_msg 2. Spi transfer begins via spi_transfer_one_message() 3. System is suspended interrupting the transfer context 4. System is resumed 6. spi_controller_resume() calls spi_start_queue() which resets cur_msg to NULL 7. Spi transfer context resumes and spi_finalize_current_message() is called which dereferences cur_msg (which is now NULL) Wait for synchronous transfers to complete before suspending by acquiring the bus mutex and setting/checking a suspend flag.

AI Score

6.7

Confidence

Low