CVE-2024-53070
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/11/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: dwc3: fix fault at system suspend if device was already runtime suspended<br />
<br />
If the device was already runtime suspended then during system suspend<br />
we cannot access the device registers else it will crash.<br />
<br />
Also we cannot access any registers after dwc3_core_exit() on some<br />
platforms so move the dwc3_enable_susphy() call to the top.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15.170 (including) | 5.15.172 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.115 (including) | 6.1.117 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.59 (including) | 6.6.61 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.11.5 (including) | 6.11.8 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/06b98197b69e2f2af9cb1991ee0b1c876edf7b86
- https://git.kernel.org/stable/c/4abc5ee334fe4aba50461c45fdaaa4c5e5c57789
- https://git.kernel.org/stable/c/562804b1561cc248cc37746a1c96c83cab1d7209
- https://git.kernel.org/stable/c/9cfb31e4c89d200d8ab7cb1e0bb9e6e8d621ca0b
- https://git.kernel.org/stable/c/d9e65d461a9de037e7c9d584776d025cfce6d86d
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html



