
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-48761 affects the Linux kernel's USB XHCI platform driver. The vulnerability was discovered when a crash occurred on the i.MX8QM platform during system suspend with remote wakeup enabled. The issue was disclosed on June 20, 2024 (NVD).
The vulnerability occurs in the xhci-plat driver's suspend functionality. The issue arises when the system attempts to suspend while the USB controller is in runtime suspended state. The crash happens because xhcisuspend tries to access registers through xhcidisablehubport_wake after the clock has been gated by runtime suspend. This was previously masked by the power domain driver's behavior of calling runtime resume, but became exposed after changes to the power domain handling (Kernel Commit).
When exploited, this vulnerability can cause a system crash (synchronous external abort) on affected platforms when attempting to suspend the system with USB remote wake enabled. This primarily affects systems using the XHCI platform driver with power management features (NVD).
The issue has been fixed by adding runtime resume calls before suspend operations in the xhci-plat driver. The fix ensures the clock is enabled before accessing registers during suspend operations. The patch has been merged into the Linux kernel (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."