CVE-2023-54220
Last modified
CVE-2023-54220 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix oops for port->pm on uart_change_pm() Unloading a hardware specific 8250 driver can produce error "Unable to handle kernel paging request at virtual address" about ten seconds after unloading the driver. This happens on uart_hangup() calling uart_change_pm(). Turns out commit 04e82793f068 ("serial: 8250: Reinit port->pm on port specific driver unbind") was only a partial fix. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix oops for port->pm on uart_change_pm() Unloading a hardware specific 8250 driver can produce error "Unable to handle kernel paging request at virtual address" about ten seconds after unloading the driver. This happens on uart_hangup() calling uart_change_pm(). Turns out commit 04e82793f068 ("serial: 8250: Reinit port->pm on port specific driver unbind") was only a partial fix. If the hardware specific driver has initialized port->pm function, we need to clear port->pm too. Just reinitializing port->ops does not do this. Otherwise serial8250_pm() will call port->pm() instead of serial8250_do_pm().
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 490bf37eaabb0a857ed1ae8e75d8854e41662f1c, < 66f3e55960698c874b0598277913b478ecd29573; >= c9e080c3005fd183c56ff8f4d75edb5da0765d2c, < 720a297b334e85d34099e83d1f375b92c3efedd6; >= d5cd2928d31042a7c0a01464f9a8d95be736421d, < b653289ca6460a6552c8590b75dfa84a0140a46b; >= 2c86a1305c1406f45ea780d06953c484ea1d9e6e, < bd70d0b28010d560a8be96b44fea86fe2ba016ae; >= 1ba5594739d858e524ff0f398ee1ebfe0a8b9d41, < 18e27df4f2b4e257c317ba8076f31a888f6cc64b; >= af4d6dbb1a92ea424ad1ba1d0c88c7fa2345d872, < 0c05493341d6f2097f75f0a5dbb7b53a9e8c5f6c; >= 04e82793f068d2f0ffe62fcea03d007a8cdc16a7, < 375806616f8c772c33d40e112530887b37c1a816; >= 04e82793f068d2f0ffe62fcea03d007a8cdc16a7, < dfe2aeb226fd5e19b0ee795f4f6ed8bc494c1534; 8e596aed5f2f98cf3e6e98d6fe1d689f4a319308; >= 4.14.316, < 4.14.324; >= 4.19.284, < 4.19.293; >= 5.4.244, < 5.4.255; >= 5.10.181, < 5.10.192; >= 5.15.113, < 5.15.128; >= 6.1.30, < 6.1.47; >= 6.3.4, < 6.4 |
| Linux | Linux | 6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54220?
How severe is CVE-2023-54220?
How do I fix CVE-2023-54220?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54215In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54216In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54217In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54218In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54219In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2023-5422The functions to fetch e-mail via POP3 or IMAP as well as se…9.1
- CVE-2023-54221In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54222In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54223In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2023-54224In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54225In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54226In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2023-54220?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
