
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53287 affects the Linux kernel and involves a vulnerability in the USB CDNS3 driver. The issue was discovered when the device could be scheduled during the resume process, causing atomic operation violations. The vulnerability was identified in version 6.1.20 of the Linux kernel (NVD).
The vulnerability occurs in the USB CDNS3 driver where pmruntimesetactive is called within a spin lock section. Since pmruntimesetactive will resume suppliers, this operation cannot appear in atomic operations. The issue manifests as a kernel warning: 'BUG: sleeping function called from invalid context' at drivers/base/power/runtime.c:1163, with specific indicators including inatomic():1, irqsdisabled():0, and preempt_count:1 (NVD).
The vulnerability affects the kernel's power management functionality for USB devices using the CDNS3 driver. When triggered, it can cause kernel warnings and potential system stability issues, particularly during device resume operations (Debian Tracker).
The issue has been fixed in several Linux kernel versions. Debian has addressed this in version 6.1.55-1 for bookworm and 6.5.6-1 for unstable releases. Various other distributions have also released patches to address this vulnerability (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."