In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom: bam_dma: fix runtime PM underflow
Commit dbad41e7bb5f ("dmaengine: qcom: bam_dma: check if the runtime pm enabled") caused unbalanced pm_runtime_get/put() calls when the bam is controlled remotely. This commit reverts it and just enables pm_runtime in all cases, the clk_* functions already just nop when the clock is NULL.
Also clean up a bit by removing unnecessary bamclk null checks.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-gkeopUpgrade linux-aws-5.15Upgrade linux-ibmUpgrade linuxUpgrade linux-intel-iotgUpgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-raspiUpgrade linux-oracleUpgrade linux-kvmUpgrade linux-nvidiaUpgrade linux-gkeUpgrade linux-gcp-5.15Upgrade linux-riscv-5.15Upgrade linux-lowlatencyUpgrade linux-azureUpgrade linux-intel-iotg-5.15Upgrade linux-azure-5.15Upgrade linux-realtimeUpgrade linux-gcpUpgrade linux-awsUpgrade linux-lowlatency-hwe-5.15 | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub