CVE-2023-52660

MEDIUM

Linux Kernel 5.6-6.1.83 - Denial of Service via Shared IRQ Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ handling due to shared interrupts The driver requests the interrupts as IRQF_SHARED, so the interrupt handlers can be called at any time. If such a call happens while the ISP is powered down, the SoC will hang as the driver tries to access the ISP registers. This can be reproduced even without the platform sharing the IRQ line: Enable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will hang. Fix this by adding a new field, 'irqs_enabled', which is used to bail out from the interrupt handler when the ISP is not operational.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel 5.6.0 - 6.1.83linux
linux/Kernel 6.2.0 - 6.6.23linux
linux/Kernel 6.7.0 - 6.7.11linux
Linux/Linux < 5.6
Linux/Linux 25cb42af9ffabffec499e9e69e2fd3797774ce5b - abd34206f396d3ae50cddbd5aa840b8cd7f68c63
Linux/Linux 25cb42af9ffabffec499e9e69e2fd3797774ce5b - b39b4d207d4f236a74e20d291f6356f2231fd9ee
Linux/Linux 25cb42af9ffabffec499e9e69e2fd3797774ce5b - edcf92bc66d8361c51dff953a55210e5cfd95587
Linux/Linux 25cb42af9ffabffec499e9e69e2fd3797774ce5b - ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e
Linux/Linux 5.6
Linux/Linux 6.1.83 - 6.1.*
... and 5 more
Published May 17, 2024
Tracked Since Feb 18, 2026