ACK: [SRU][Jammy][Focal][PATCH v2 0/1] CVE-2023-22995

Manuel Diewald manuel.diewald at canonical.com
Thu Jan 11 10:58:39 UTC 2024


On Tue, Jan 09, 2024 at 08:02:43AM -0500, Bethany Jamison wrote:
> [Impact]
> 
> In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in
> drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.
> 
> [Fix]
> 
> Jammy: Clean cherry-pick.
> Focal: I had a missing context merge conflict - I removed the conflicting line 
> from the incoming change because it wasn't apart of this cve fix and wasn't 
> applicable to Focal.
> 
> [Test Case]
> 
> Compile and boot test.
> 
> [Where problems could occur]
> 
> Problems could occur is dwc3 usb driver, when registering device.
> 
> v2:
> added backporting details to Focal
> 
> Miaoqian Lin (1):
>   usb: dwc3: dwc3-qcom: Add missing platform_device_put() in
>     dwc3_qcom_acpi_register_core
> 
>  drivers/usb/dwc3/dwc3-qcom.c | 8 +++++++-
>  1 file changed, 7 insertions(+), 1 deletion(-)
> 
> -- 
> 2.34.1
> 
> 
> -- 
> kernel-team mailing list
> kernel-team at lists.ubuntu.com
> https://lists.ubuntu.com/mailman/listinfo/kernel-team

Acked-by: Manuel Diewald <manuel.diewald at canonical.com>

-- 
 Manuel



More information about the kernel-team mailing list