Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-52498— PM: sleep: Fix possible deadlocks in core system-wide PM code

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于core system-wide PM代码存在死锁问题。

AI Predicted 5.3 Difficulty: Hard EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1562

Affected Version Matrix 22

VendorProduct Version RangeStatus
Linux Linux 0552e05fdfea191a2cf3a0abd33574b5ef9ca818< f46eb832389f162ad13cb780d0b8cde93641990d affected
0552e05fdfea191a2cf3a0abd33574b5ef9ca818< a1d62c775b07213c73f81ae842424c74dd14b5f0 affected
0552e05fdfea191a2cf3a0abd33574b5ef9ca818< e1c9d32c98309ae764893a481552d3f99d46cb34 affected
0552e05fdfea191a2cf3a0abd33574b5ef9ca818< e681e29d1f59a04ef773296e4bebb17b1b79f8fe affected
0552e05fdfea191a2cf3a0abd33574b5ef9ca818< 9bd3dce27b01c51295b60e1433e1dadfb16649f7 affected
0552e05fdfea191a2cf3a0abd33574b5ef9ca818< 7839d0078e0d5e6cc2fa0b0dfbee71de74f1e557 affected
5d56260c5e9fdbbba59655f63622f6159bf0e595 affected
76d587bd579a08ddcd51274c6d9fff4e885e184d affected
… +14 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52498

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PM: sleep: Fix possible deadlocks in core system-wide PM code
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Fix possible deadlocks in core system-wide PM code It is reported that in low-memory situations the system-wide resume core code deadlocks, because async_schedule_dev() executes its argument function synchronously if it cannot allocate memory (and not only in that case) and that function attempts to acquire a mutex that is already held. Executing the argument function synchronously from within dpm_async_fn() may also be problematic for ordering reasons (it may cause a consumer device's resume callback to be invoked before a requisite supplier device's one, for example). Address this by changing the code in question to use async_schedule_dev_nocall() for scheduling the asynchronous execution of device suspend and resume functions and to directly run them synchronously if async_schedule_dev_nocall() returns false.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于core system-wide PM代码存在死锁问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0552e05fdfea191a2cf3a0abd33574b5ef9ca818 ~ f46eb832389f162ad13cb780d0b8cde93641990d -
Linux Linux 5.6 -

II. Public POCs for CVE-2023-52498

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52498

请登录查看更多情报信息。

Mailing List Discussions for CVE-2023-52498 (1)

Other References for CVE-2023-52498 (5)

Same Patch Batch · Linux · 2024-02-29 · 53 CVEs total

CVE-2023-52480 9.8 CRITICAL ksmbd: fix race condition between session lookup and expire
CVE-2023-52478 8.8 HIGH HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
CVE-2023-52479 8.8 HIGH ksmbd: fix uaf in smb20_oplock_break_ack
CVE-2024-26620 8.2 HIGH s390/vfio-ap: always filter entire AP matrix
CVE-2021-47060 7.8 HIGH KVM: Stop looking for coalesced MMIO zones if the bus is destroyed
CVE-2023-52483 7.8 HIGH mctp: perform route lookups under a RCU read-side lock
CVE-2023-52486 7.8 HIGH drm: Don't unref the same fb many times by mistake due to deadlock handling
CVE-2021-47061 7.8 HIGH KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU
CVE-2021-47068 7.8 HIGH net/nfc: fix use-after-free llcp_sock_bind/connect
CVE-2023-52491 7.8 HIGH media: mtk-jpeg: Fix use after free bug due to error path handling in mtk_jpeg_dec_device_
CVE-2024-26608 7.8 HIGH ksmbd: fix global oob in ksmbd_nl_policy
CVE-2024-26610 7.8 HIGH wifi: iwlwifi: fix a memory corruption
CVE-2024-26614 7.8 HIGH tcp: make sure init the accept_queue's spinlocks once
CVE-2024-26617 7.8 HIGH fs/proc/task_mmu: move mmu notification mechanism inside mm lock
CVE-2024-26611 7.5 HIGH xsk: fix usage of multi-buffer BPF helpers for ZC XDP
CVE-2021-47066 7.1 HIGH async_xor: increase src_offs when dropping destination page
CVE-2021-47055 7.1 HIGH mtd: require write permissions for locking and badblock ioctls
CVE-2023-52497 7.1 HIGH erofs: fix lz4 inplace decompression
CVE-2021-47067 soc/tegra: regulators: Fix locking up when voltage-spread is out of range
CVE-2024-26612 netfs, fscache: Prevent Oops in fscache_put_cache()

Showing top 20 of 53 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52498

No comments yet


Leave a comment