« Volver al listado

CVE-2023-54159

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: mtu3: fix kernel panic at qmu transfer done irq handler

When handle qmu transfer irq, it will unlock @mtu->lock before give back request, if another thread handle disconnect event at the same time, and try to disable ep, it may lock @mtu->lock and free qmu ring, then qmu irq hanlder may get a NULL gpd, avoid the KE by checking gpd's value before handling it.

e.g. qmu done irq on cpu0 thread running on cpu1

[1]: goto [0] to handle next gpd, and next gpd may be NULL.

Detalles técnicos trazas, registros y código del informe original
qmu_done_tx()
  handle gpd [0]
    mtu3_requ_complete()        mtu3_gadget_ep_disable()
      unlock @mtu->lock
        give back request         lock @mtu->lock
                                    mtu3_ep_disable()
                                      mtu3_gpd_ring_free()
                                   unlock @mtu->lock
      lock @mtu->lock
    get next gpd [1]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54159",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "26ca30516b2c49dd04c134cbdf122311c538df98",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "012936502a9cb7b0604e85bb961eb15e2bb40dd9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "ee53a7a88027cea765c68f3b00a50b8f58d6f786",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "f26273428657ef4ca74740e578ae45a3be492f6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "b636aff94a67be46582d4321d11743f1a10cc2c1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "3a7d4959560a2ee493ef222e3b63d359365f41ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "48e0d3735aa557a8adaf94632ca3cf78798e8505",
              "lessThan": "d28f4091ea7ec3510fd6a3c6d433234e7a2bef14",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/mtu3/mtu3_qmu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.243",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.180",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.111",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.28",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.15",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.3.*"
            },
            {
              "status": "unaffected",
              "version": "6.4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/mtu3/mtu3_qmu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:17.960",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/012936502a9cb7b0604e85bb961eb15e2bb40dd9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/26ca30516b2c49dd04c134cbdf122311c538df98",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3a7d4959560a2ee493ef222e3b63d359365f41ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b636aff94a67be46582d4321d11743f1a10cc2c1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d28f4091ea7ec3510fd6a3c6d433234e7a2bef14",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee53a7a88027cea765c68f3b00a50b8f58d6f786",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f26273428657ef4ca74740e578ae45a3be492f6f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: fix kernel panic at qmu transfer done irq handler\n\nWhen handle qmu transfer irq, it will unlock @mtu->lock before give back\nrequest, if another thread handle disconnect event at the same time, and\ntry to disable ep, it may lock @mtu->lock and free qmu ring, then qmu\nirq hanlder may get a NULL gpd, avoid the KE by checking gpd's value before\nhandling it.\n\ne.g.\nqmu done irq on cpu0                 thread running on cpu1\n\nqmu_done_tx()\n  handle gpd [0]\n    mtu3_requ_complete()        mtu3_gadget_ep_disable()\n      unlock @mtu->lock\n        give back request         lock @mtu->lock\n                                    mtu3_ep_disable()\n                                      mtu3_gpd_ring_free()\n                                   unlock @mtu->lock\n      lock @mtu->lock\n    get next gpd [1]\n\n[1]: goto [0] to handle next gpd, and next gpd may be NULL."
    }
  ],
  "lastModified": "2026-06-17T06:46:54.613",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}