CVE-2024-53070
Estado: ModificadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
usb: dwc3: fix fault at system suspend if device was already runtime suspended
If the device was already runtime suspended then during system suspend we cannot access the device registers else it will crash.
Also we cannot access any registers after dwc3_core_exit() on some platforms so move the dwc3_enable_susphy() call to the top.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/06b98197b69e2f2af9cb1991ee0b1c876edf7b86
- https://git.kernel.org/stable/c/4abc5ee334fe4aba50461c45fdaaa4c5e5c57789
- https://git.kernel.org/stable/c/562804b1561cc248cc37746a1c96c83cab1d7209
- https://git.kernel.org/stable/c/9cfb31e4c89d200d8ab7cb1e0bb9e6e8d621ca0b
- https://git.kernel.org/stable/c/d9e65d461a9de037e7c9d584776d025cfce6d86d
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-53070",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-53070",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-10-01T20:12:26.967157Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "073530898ebf44a9418434e899cfa9ca86945333",
"lessThan": "d9e65d461a9de037e7c9d584776d025cfce6d86d",
"versionType": "git"
},
{
"status": "affected",
"version": "85ca88f93162acb94dbcb26d0ee2b145864d14a1",
"lessThan": "562804b1561cc248cc37746a1c96c83cab1d7209",
"versionType": "git"
},
{
"status": "affected",
"version": "4fad7370086797afe6471493e3a5f36add8c48a7",
"lessThan": "4abc5ee334fe4aba50461c45fdaaa4c5e5c57789",
"versionType": "git"
},
{
"status": "affected",
"version": "a690a9e38e6ba819789074388de7cff06425ef5b",
"lessThan": "06b98197b69e2f2af9cb1991ee0b1c876edf7b86",
"versionType": "git"
},
{
"status": "affected",
"version": "705e3ce37bccdf2ed6f848356ff355f480d51a91",
"lessThan": "9cfb31e4c89d200d8ab7cb1e0bb9e6e8d621ca0b",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/dwc3/core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.15.170",
"lessThan": "5.15.172",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.115",
"lessThan": "6.1.117",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.59",
"lessThan": "6.6.61",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.11.5",
"lessThan": "6.11.8",
"versionType": "semver"
}
],
"programFiles": [
"drivers/usb/dwc3/core.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-11-19T18:15:26.700",
"references": [
{
"url": "https://git.kernel.org/stable/c/06b98197b69e2f2af9cb1991ee0b1c876edf7b86",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4abc5ee334fe4aba50461c45fdaaa4c5e5c57789",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/562804b1561cc248cc37746a1c96c83cab1d7209",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9cfb31e4c89d200d8ab7cb1e0bb9e6e8d621ca0b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d9e65d461a9de037e7c9d584776d025cfce6d86d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: fix fault at system suspend if device was already runtime suspended\n\nIf the device was already runtime suspended then during system suspend\nwe cannot access the device registers else it will crash.\n\nAlso we cannot access any registers after dwc3_core_exit() on some\nplatforms so move the dwc3_enable_susphy() call to the top."
},
{
"lang": "es",
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: usb: dwc3: se corrige un error en la suspensión del sistema si el dispositivo ya estaba suspendido en tiempo de ejecución. Si el dispositivo ya estaba suspendido en tiempo de ejecución, durante la suspensión del sistema no podemos acceder a los registros del dispositivo, de lo contrario, se bloqueará. Además, no podemos acceder a ningún registro después de dwc3_core_exit() en algunas plataformas, por lo que movemos la llamada dwc3_enable_susphy() al principio."
}
],
"lastModified": "2026-06-17T08:08:11.823",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CC09466-A4C0-4FE6-AC81-F620B65EC4AF",
"versionEndExcluding": "5.15.172",
"versionStartIncluding": "5.15.170"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CACEF6C4-89D7-488E-8023-41C8325AA271",
"versionEndExcluding": "6.1.117",
"versionStartIncluding": "6.1.115"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "962E4D7B-164B-4604-A273-17BDEBC12DA1",
"versionEndExcluding": "6.6.61",
"versionStartIncluding": "6.6.59"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "744A9D07-6FE7-48A4-BA82-4A599235CEC6",
"versionEndExcluding": "6.11.8",
"versionStartIncluding": "6.11.5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}