CVE-2023-52457

    Dashboard / Vulnerabilities / CVE-2023-52457

    CVE-2023-52457

    Published: 23 Feb 2024Last Modified: 8 Oct 2026

    Summary: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed

    Details: In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from .remove() makes the driver core emit the little helpful error message: remove callback returned a non-zero value. This will be ignored. and then remove the device anyhow. So all resources that were not freed are leaked in this case. Skipping serial8250_unregister_port() has the potential to keep enough of the UART around to trigger a use-after-free. So replace the error return (and with it the little helpful error message) by a more useful error message and continue to cleanup.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 2d66412563ef8953e2bac2d98d2d832b3f3f49cd

    Affected versions

    v5.4.267
    v5.4.266
    v5.4.265
    v5.4.264
    v5.4.263
    v5.4.262
    v5.4.261
    v5.4.260
    v5.4.259
    v5.4.258
    v5.4.257
    v5.4.256
    v5.4.255
    v5.4.254
    v5.4.253
    v5.4.252
    v5.4.251
    v5.4.250
    v5.4.249
    v5.4.248
    v5.4.247
    v5.4.246
    v5.4.245
    v5.4.244
    v5.4.243
    v5.4.242
    v5.4.241
    v5.4.240
    v5.4.239
    v5.4.238
    v5.4.237
    v5.4.236
    v5.4.235
    v5.4.234
    v5.4.233
    v5.4.232
    v5.4.231
    v5.4.230
    v5.4.229
    v5.4.228
    v5.4.227
    v5.4.226
    v5.4.225

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-52457 | CVE-DB