vulnerability
Ubuntu: (CVE-2023-52660): linux-raspi-realtime vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | May 17, 2024 | Feb 11, 2025 | Apr 16, 2026 |
Description
In the Linux kernel, the following vulnerability has been resolved:
media: rkisp1: Fix IRQ handling due to shared interrupts
The driver requests the interrupts as IRQF_SHARED, so the interrupt
handlers can be called at any time. If such a call happens while the ISP
is powered down, the SoC will hang as the driver tries to access the
ISP registers.
This can be reproduced even without the platform sharing the IRQ line:
Enable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will
hang.
Fix this by adding a new field, 'irqs_enabled', which is used to bail
out from the interrupt handler when the ISP is not operational.
Solution
References
- CVE-2023-52660
- https://attackerkb.com/topics/CVE-2023-52660
- EUVD-EUVD-2023-57284
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57284
- https://git.kernel.org/linus/ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e
- https://git.kernel.org/stable/c/abd34206f396d3ae50cddbd5aa840b8cd7f68c63
- https://git.kernel.org/stable/c/b39b4d207d4f236a74e20d291f6356f2231fd9ee
- https://git.kernel.org/stable/c/edcf92bc66d8361c51dff953a55210e5cfd95587
- https://git.kernel.org/stable/c/ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e
- https://www.cve.org/CVERecord?id=CVE-2023-52660
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.