ACK/Cmnt: [SRU][Jammy][Focal][PATCH v2 0/1] CVE-2023-22995

Tim Gardner tim.gardner at canonical.com
Tue Jan 9 14:53:22 UTC 2024


On 1/9/24 6:02 AM, Bethany Jamison wrote:
> [Impact]
> 
> In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in
> drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.
> 
> [Fix]
> 
> Jammy: Clean cherry-pick.
> Focal: I had a missing context merge conflict - I removed the conflicting line
> from the incoming change because it wasn't apart of this cve fix and wasn't
> applicable to Focal.
> 
> [Test Case]
> 
> Compile and boot test.
> 
> [Where problems could occur]
> 
> Problems could occur is dwc3 usb driver, when registering device.
> 
> v2:
> added backporting details to Focal
> 
> Miaoqian Lin (1):
>    usb: dwc3: dwc3-qcom: Add missing platform_device_put() in
>      dwc3_qcom_acpi_register_core
> 
>   drivers/usb/dwc3/dwc3-qcom.c | 8 +++++++-
>   1 file changed, 7 insertions(+), 1 deletion(-)
> 
Acked-by: Tim Gardner <tim.gardner at canonical.com>

v1 had a Focal backport. Perhaps the list response went into your SPAM 
folder. I also look at the list server 
(https://lists.ubuntu.com/archives/kernel-team/) when I see an anomaly 
like that. As often as not it is my local email client that is mistaken, 
or one of my filters has hijacked the message for some arcane reason. In 
this case it looks like you got it right the first time. 
(https://lists.ubuntu.com/archives/kernel-team/2024-January/147989.html)

-- 
-----------
Tim Gardner
Canonical, Inc




More information about the kernel-team mailing list