Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: hi846: fix usage of pm_runtime_get_if_in_use() pm_runtime_get_if_in_use() does not only return nonzero values when the device is in use, it can return a negative errno too. And especially during resuming from system suspend, when runtime pm is not yet up again, -EAGAIN is being returned, so the subsequent pm_runtime_put() call results in a refcount underflow. Fix system-resume by handling -EAGAIN of pm_runtime_get_if_in_use().
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.16, < 6.1.39 |
References
- https://git.kernel.org/stable/c/04fc06f6dc1592ed5d675311ac50d8fba5db62abPatch
- https://git.kernel.org/stable/c/42ec6269f98edd915ee37da3c6456bb6243ea56aPatch
- https://git.kernel.org/stable/c/c5dcd7a19f1ed8fe98384f3a9444c7c53befd74ePatch
FAQ
What is CVE-2023-53177?
CVE-2023-53177 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: media: hi846: fix usage of pm_runtime_get_if_in_use() pm_runtime_get_if_in_use() does not only return nonzero values when the devi...
How severe is CVE-2023-53177?
CVE-2023-53177 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53177?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.