hid: cp2112: Fix duplicate workqueue initialization
Published May 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Previously the cp2112 driver called INIT_DELAYED_WORK within cp2112_gpio_irq_startup, resulting in duplicate initilizations of the workqueue on subsequent IRQ startups following an initial request. This resulted in a warning in set_work_data in workqueue.c, as well as a rare NULL dereference within process_one_work in workqueue.c.
Initialize the workqueue within _probe instead.
Affected products
-
Affected
- ≥ 13de9cca514e, < 012d0c66f939
- ≥ 13de9cca514e, < 3d959406c8ff
- ≥ 13de9cca514e, < 727203e6e7e7
- ≥ 13de9cca514e, < bafb12b629b7
- ≥ 13de9cca514e, < df0daac27094
- ≥ 13de9cca514e, < e3c2d2d144c0
- ≥ 13de9cca514e, < eb1121fac798
- ≥ 13de9cca514e, < fb5718bc6733
-
Affected
- 4.10
Unaffected
- ≥ 0, < 4.10
- ≥ 4.19.299, ≤ 4.19.*
- ≥ 5.10.201, ≤ 5.10.*
- ≥ 5.15.139, ≤ 5.15.*
- ≥ 5.4.261, ≤ 5.4.*
- ≥ 6.1.63, ≤ 6.1.*
- ≥ 6.5.12, ≤ 6.5.*
- ≥ 6.6.2, ≤ 6.6.*
- 6.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.10 · < 4.19.299
- ≥ 4.20 · < 5.4.261
- ≥ 5.5 · < 5.10.201
- ≥ 5.11 · < 5.15.139
- ≥ 5.16 · < 6.1.63
- ≥ 6.2 · < 6.5.12
- ≥ 6.6 · < 6.6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-52853 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282624 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59566 Advisory
- https://git.kernel.org/stable/c/012d0c66f9392a99232ac28217229f32dd3a70cf Patch
- https://git.kernel.org/stable/c/3d959406c8fff2334d83d0c352d54fd6f5b2e7cd Patch
- https://git.kernel.org/stable/c/727203e6e7e7020e1246fc1628cbdb8d90177819 Patch
- https://git.kernel.org/stable/c/bafb12b629b7c3ad59812dd1ac1b0618062e0e38 Patch
- https://git.kernel.org/stable/c/df0daac2709473531d6a3472997cc65301ac06d6 Patch
- https://git.kernel.org/stable/c/e3c2d2d144c082dd71596953193adf9891491f42 Patch
- https://git.kernel.org/stable/c/eb1121fac7986b30915ba20c5a04cc01fdcf160c Patch
- https://git.kernel.org/stable/c/fb5718bc67337dde1528661f419ffcf275757592 Patch
- https://lore.kernel.org/linux-cve-announce/2024052115-CVE-2023-52853-5fd3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52853
- https://www.cve.org/CVERecord?id=CVE-2023-52853
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data