soundwire: bus: Fix unbalanced pm_runtime_put() causing usage count underflow
Published Dec 30, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
This reverts commit 443a98e649b4 ("soundwire: bus: use pm_runtime_resume_and_get()")
Change calls to pm_runtime_resume_and_get() back to pm_runtime_get_sync(). This fixes a usage count underrun caused by doing a pm_runtime_put() even though pm_runtime_resume_and_get() returned an error.
The three affected functions ignore -EACCES error from trying to get pm_runtime, and carry on, including a put at the end of the function. But pm_runtime_resume_and_get() does not increment the usage count if it returns an error. So in the -EACCES case you must not call pm_runtime_put().
The documentation for pm_runtime_get_sync() says: "Consider using pm_runtime_resume_and_get() ... as this is likely to result in cleaner code."
In this case I don't think it results in cleaner code because the pm_runtime_put() at the end of the function would have to be conditional on the return value from pm_runtime_resume_and_get() at the top of the function.
pm_runtime_get_sync() doesn't have this problem because it always increments the count, so always needs a put. The code can just flow through and do the pm_runtime_put() unconditionally.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.19
- Version 6.1.30StatusunaffectedConstraints<=6.1.*
- Version 6.3.4StatusunaffectedConstraints<=6.3.*
- Version 6.4StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This affects systems with SoundWire audio hardware. The underflow can cause power management state inconsistencies but typically does not crash the system. The issue occurs only in specific error scenarios during device power state transitions.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.20% (0.00198) | 8.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.17% (0.00166) | 6.21th | v5 (v2026.06.15) |
| Dec 31, 2025 | 0.02% (0.00017) | 3.13th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2023-54259 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426250 Issue Tracking
- https://git.kernel.org/stable/c/203aa4374c433159f163acde2d0bd4118f23bbaf
- https://git.kernel.org/stable/c/4e5e9da139c007dfc397a159093b4c4187ee67fa
- https://git.kernel.org/stable/c/e9537962519e88969f5f69cd0571eb4f6984403c
- https://lore.kernel.org/linux-cve-announce/2025123057-CVE-2023-54259-64ee@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-54259
- https://www.cve.org/CVERecord?id=CVE-2023-54259
Change history (0)
No recorded changes yet.