-

CVE-2023-53356

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_serial: Add null pointer check in gserial_suspend

Consider a case where gserial_disconnect has already cleared
gser->ioport. And if gserial_suspend gets called afterwards,
it will lead to accessing of gser->ioport and thus causing
null pointer dereference.

Avoid this by adding a null pointer check. Added a static
spinlock to prevent gser->ioport from becoming null after
the newly added null pointer check.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 2788a3553f7497075653210b42e2aeb6ba95e28e
Version aba3a8d01d623a5efef48ab8e78752d58d4c90c3
Status affected
Version < a8ea7ed644cbf6314b5b0136b5398754b549fb8f
Version aba3a8d01d623a5efef48ab8e78752d58d4c90c3
Status affected
Version < e60a827ac074ce6bd58305fe5a86afab5fce6a04
Version aba3a8d01d623a5efef48ab8e78752d58d4c90c3
Status affected
Version < 374447e3367767156405bedd230c5d391f4b7962
Version aba3a8d01d623a5efef48ab8e78752d58d4c90c3
Status affected
Version < 2f6ecb89fe8feb2b60a53325b0eeb9866d88909a
Version aba3a8d01d623a5efef48ab8e78752d58d4c90c3
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.8
Status affected
Version < 5.8
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.188
Status unaffected
Version <= 5.15.*
Version 5.15.121
Status unaffected
Version <= 6.1.*
Version 6.1.39
Status unaffected
Version <= 6.4.*
Version 6.4.4
Status unaffected
Version <= *
Version 6.5
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.048
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string