Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2023-54159

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/12/2025
Última modificación:
24/12/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: mtu3: fix kernel panic at qmu transfer done irq handler<br /> <br /> When handle qmu transfer irq, it will unlock @mtu-&gt;lock before give back<br /> request, if another thread handle disconnect event at the same time, and<br /> try to disable ep, it may lock @mtu-&gt;lock and free qmu ring, then qmu<br /> irq hanlder may get a NULL gpd, avoid the KE by checking gpd&amp;#39;s value before<br /> handling it.<br /> <br /> e.g.<br /> qmu done irq on cpu0 thread running on cpu1<br /> <br /> qmu_done_tx()<br /> handle gpd [0]<br /> mtu3_requ_complete() mtu3_gadget_ep_disable()<br /> unlock @mtu-&gt;lock<br /> give back request lock @mtu-&gt;lock<br /> mtu3_ep_disable()<br /> mtu3_gpd_ring_free()<br /> unlock @mtu-&gt;lock<br /> lock @mtu-&gt;lock<br /> get next gpd [1]<br /> <br /> [1]: goto [0] to handle next gpd, and next gpd may be NULL.

Impacto