Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-52884— Input: cyapa - add missing input core locking to suspend/resume functions

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于Input模块存在问题。

AI Predicted 5.5 Difficulty: Easy EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux d69f0a43c677e8afc67a222e1e7b51b9acc69cd3< f99809fdeb50d65bcbc1661ef391af94eebb8a75 affected
d69f0a43c677e8afc67a222e1e7b51b9acc69cd3< 9400caf566f65c703e99d95f87b00c4b445627a7 affected
d69f0a43c677e8afc67a222e1e7b51b9acc69cd3< a4c638ab25786bd5aab5978fe51b2b9be16a4ebd affected
d69f0a43c677e8afc67a222e1e7b51b9acc69cd3< a5fc298fa8f67cf1f0e1fc126eab70578cd40adc affected
d69f0a43c677e8afc67a222e1e7b51b9acc69cd3< 7b4e0b39182cf5e677c1fc092a3ec40e621c25b6 affected
5.11 affected
< 5.11 unaffected
5.15.161≤ 5.15.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-52884

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Input: cyapa - add missing input core locking to suspend/resume functions
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Input: cyapa - add missing input core locking to suspend/resume functions Grab input->mutex during suspend/resume functions like it is done in other input drivers. This fixes the following warning during system suspend/resume cycle on Samsung Exynos5250-based Snow Chromebook: ------------[ cut here ]------------ WARNING: CPU: 1 PID: 1680 at drivers/input/input.c:2291 input_device_enabled+0x68/0x6c Modules linked in: ... CPU: 1 PID: 1680 Comm: kworker/u4:12 Tainted: G W 6.6.0-rc5-next-20231009 #14109 Hardware name: Samsung Exynos (Flattened Device Tree) Workqueue: events_unbound async_run_entry_fn unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x58/0x70 dump_stack_lvl from __warn+0x1a8/0x1cc __warn from warn_slowpath_fmt+0x18c/0x1b4 warn_slowpath_fmt from input_device_enabled+0x68/0x6c input_device_enabled from cyapa_gen3_set_power_mode+0x13c/0x1dc cyapa_gen3_set_power_mode from cyapa_reinitialize+0x10c/0x15c cyapa_reinitialize from cyapa_resume+0x48/0x98 cyapa_resume from dpm_run_callback+0x90/0x298 dpm_run_callback from device_resume+0xb4/0x258 device_resume from async_resume+0x20/0x64 async_resume from async_run_entry_fn+0x40/0x15c async_run_entry_fn from process_scheduled_works+0xbc/0x6a8 process_scheduled_works from worker_thread+0x188/0x454 worker_thread from kthread+0x108/0x140 kthread from ret_from_fork+0x14/0x28 Exception stack(0xf1625fb0 to 0xf1625ff8) ... ---[ end trace 0000000000000000 ]--- ... ------------[ cut here ]------------ WARNING: CPU: 1 PID: 1680 at drivers/input/input.c:2291 input_device_enabled+0x68/0x6c Modules linked in: ... CPU: 1 PID: 1680 Comm: kworker/u4:12 Tainted: G W 6.6.0-rc5-next-20231009 #14109 Hardware name: Samsung Exynos (Flattened Device Tree) Workqueue: events_unbound async_run_entry_fn unwind_backtrace from show_stack+0x10/0x14 show_stack from dump_stack_lvl+0x58/0x70 dump_stack_lvl from __warn+0x1a8/0x1cc __warn from warn_slowpath_fmt+0x18c/0x1b4 warn_slowpath_fmt from input_device_enabled+0x68/0x6c input_device_enabled from cyapa_gen3_set_power_mode+0x13c/0x1dc cyapa_gen3_set_power_mode from cyapa_reinitialize+0x10c/0x15c cyapa_reinitialize from cyapa_resume+0x48/0x98 cyapa_resume from dpm_run_callback+0x90/0x298 dpm_run_callback from device_resume+0xb4/0x258 device_resume from async_resume+0x20/0x64 async_resume from async_run_entry_fn+0x40/0x15c async_run_entry_fn from process_scheduled_works+0xbc/0x6a8 process_scheduled_works from worker_thread+0x188/0x454 worker_thread from kthread+0x108/0x140 kthread from ret_from_fork+0x14/0x28 Exception stack(0xf1625fb0 to 0xf1625ff8) ... ---[ end trace 0000000000000000 ]---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于Input模块存在问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux d69f0a43c677e8afc67a222e1e7b51b9acc69cd3 ~ f99809fdeb50d65bcbc1661ef391af94eebb8a75 -
Linux Linux 5.11 -

II. Public POCs for CVE-2023-52884

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52884

登录查看更多情报信息。

Other References for CVE-2023-52884 (5)

Same Patch Batch · Linux · 2024-06-21 · 40 CVEs total

CVE-2024-36288 9.8 CRITICAL SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
CVE-2024-38381 8.8 HIGH nfc: nci: Fix uninit-value in nci_rx_work
CVE-2024-33619 7.8 HIGH efi: libstub: only free priv.runtime_map when allocated
CVE-2024-38628 7.8 HIGH usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
CVE-2024-36477 7.8 HIGH tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer
CVE-2024-38626 7.8 HIGH fuse: clear FR_SENT when re-adding requests into pending list
CVE-2024-36286 7.8 HIGH netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
CVE-2024-38623 7.8 HIGH fs/ntfs3: Use variable length array instead of fixed size
CVE-2024-38635 7.8 HIGH soundwire: cadence: fix invalid PDI offset
CVE-2024-38388 7.8 HIGH ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup
CVE-2024-38659 7.3 HIGH enic: Validate length of nl attributes in enic_set_vf_port
CVE-2024-36481 tracing/probes: fix error check in parse_btf_field()
CVE-2024-38662 bpf: Allow delete from sockmap/sockhash only if update is allowed
CVE-2024-38637 greybus: lights: check return of get_channel_from_mode
CVE-2024-38636 f2fs: multidev: fix to recognize valid zero block address
CVE-2024-38780 dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
CVE-2024-39277 dma-mapping: benchmark: handle NUMA_NO_NODE correctly
CVE-2024-38634 serial: max3100: Lock port->lock when calling uart_handle_cts_change()
CVE-2024-34777 dma-mapping: benchmark: fix node id validation
CVE-2024-38633 serial: max3100: Update uart_driver_registered on driver removal

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52884

No comments yet


Leave a comment