SB20240608189 - Race condition in Linux kernel soc mediatek driver
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2023-52645)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition within the scpsys_add_subdomain() and scpsys_remove_one_domain() functions in drivers/soc/mediatek/mtk-pm-domains.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/475426ad1ae0bfdfd8f160ed9750903799392438
- https://git.kernel.org/stable/c/339ddc983bc1622341d95f244c361cda3da3a4ff
- https://git.kernel.org/stable/c/f83b9abee9faa4868a6fac4669b86f4c215dae25
- https://git.kernel.org/stable/c/3cd1d92ee1dbf3e8f988767eb75f26207397792b
- https://git.kernel.org/stable/c/c41336f4d69057cbf88fed47951379b384540df5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.150
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.80
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.18
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7.6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.8