« Volver al listado

CVE-2023-53758

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

spi: atmel-quadspi: Free resources even if runtime resume failed in .remove()

An early error exit in atmel_qspi_remove() doesn't prevent the device unbind. So this results in an spi controller with an unbound parent and unmapped register space (because devm_ioremap_resource() is undone). So using the remaining spi controller probably results in an oops.

Instead unregister the controller unconditionally and only skip hardware access and clk disable.

Also add a warning about resume failing and return zero unconditionally. The latter has the only effect to suppress a less helpful error message by the spi core.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-53758",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4a2f83b7f78092a6d9e98fb5573d8f4b79c56336",
              "lessThan": "f6974fb20499e3b6522daa7aec822aac11dfcf42",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4a2f83b7f78092a6d9e98fb5573d8f4b79c56336",
              "lessThan": "618770d4d8e40b7f8ed9eb5f210cd9164dfac47d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4a2f83b7f78092a6d9e98fb5573d8f4b79c56336",
              "lessThan": "77806d7c9bebe40a8cdce2b8d30fbe6511745df8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4a2f83b7f78092a6d9e98fb5573d8f4b79c56336",
              "lessThan": "9448bc1dee65f86c0fe64d9dea8b410af0586886",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/spi/atmel-quadspi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.28",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.15",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.3.*"
            },
            {
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/spi/atmel-quadspi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-08T02:15:51.527",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/618770d4d8e40b7f8ed9eb5f210cd9164dfac47d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/77806d7c9bebe40a8cdce2b8d30fbe6511745df8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9448bc1dee65f86c0fe64d9dea8b410af0586886",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f6974fb20499e3b6522daa7aec822aac11dfcf42",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: atmel-quadspi: Free resources even if runtime resume failed in .remove()\n\nAn early error exit in atmel_qspi_remove() doesn't prevent the device\nunbind. So this results in an spi controller with an unbound parent\nand unmapped register space (because devm_ioremap_resource() is undone).\nSo using the remaining spi controller probably results in an oops.\n\nInstead unregister the controller unconditionally and only skip hardware\naccess and clk disable.\n\nAlso add a warning about resume failing and return zero unconditionally.\nThe latter has the only effect to suppress a less helpful error message by\nthe spi core."
    }
  ],
  "lastModified": "2026-06-17T06:46:01.153",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}