Linux Kernel Vulnerability in cdns3 USB Controller by Freescale
CVE-2023-53287

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2025

What is CVE-2023-53287?

A flaw has been identified in the Linux kernel related to the cdns3 USB controller, where the active state of the device is incorrectly managed during the resume process. This oversight allows device scheduling during atomic operations, leading to potential kernel warnings and unstable behavior. Specifically, calls to pm_runtime_set_active must be handled outside of the spin lock to prevent disruptions to the struct cdns data structure, thus ensuring smoother operation and reliability in the kernel.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.