NOTICE UPDATED - April, 25th 2024

NIST has updated the NVD program announcement page with additional information regarding recent concerns and the temporary delays in enrichment efforts.

CVE-2023-52457 Detail


In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from .remove() makes the driver core emit the little helpful error message: remove callback returned a non-zero value. This will be ignored. and then remove the device anyhow. So all resources that were not freed are leaked in this case. Skipping serial8250_unregister_port() has the potential to keep enough of the UART around to trigger a use-after-free. So replace the error return (and with it the little helpful error message) by a more useful error message and continue to cleanup.


CVSS 4.0 Severity and Metrics:

NVD assessment not yet provided.

NVD Analysts use publicly available information to associate vector strings and CVSS scores. We also display any CVSS information provided within the CVE List from the CNA.

Note: NVD Analysts have not published a CVSS score for this CVE at this time. NVD Analysts use publicly available information at the time of analysis to associate CVSS vector strings.

References to Advisories, Solutions, and Tools

Hyperlink Resource
https://git.kernel.org/stable/c/828cd829483f0cda920710997aed79130b0af690 Patch 
https://git.kernel.org/stable/c/887a558d0298d36297daea039954c39940228d9b Patch 
https://git.kernel.org/stable/c/95e4e0031effad9837af557ecbfd4294a4d8aeee Patch 
https://git.kernel.org/stable/c/ad90d0358bd3b4554f243a425168fc7cebe7d04e Patch 
https://git.kernel.org/stable/c/b502fb43f7fb55aaf07f6092ab44657595214b93 Patch 
https://git.kernel.org/stable/c/bc57f3ef8a9eb0180606696f586a6dcfaa175ed0 Patch 
https://git.kernel.org/stable/c/d74173bda29aba58f822175d983d07c8ed335494 Patch 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-416 Use After Free cwe source acceptance level NIST  

Known Affected Software Configurations Switch to CPE 2.2

Denotes Vulnerable Software
Change History

