SB2025050485 - Resource management error in Linux kernel typec tcpm driver
Published: May 4, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-53048)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the tcpm_ams_start() and vdm_run_state_machine() functions in drivers/usb/typec/tcpm/tcpm.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/abfc4fa28f0160df61c7149567da4f6494dfb488
- https://git.kernel.org/stable/c/bb579b3f75c60bf488a7c36e092e8be583407d53
- https://git.kernel.org/stable/c/d55ca2d2ea1a7ec553213986993fba8c0257381c
- https://git.kernel.org/stable/c/e37d2c489d71e94ed4a39529bc9520a7fd983d42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.9