GHSA-c6r8-8m99-q662unknown
In the Linux kernel, the following vulnerability has been resolved: watchdog: msc313e: Fix clock...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
watchdog: msc313e: Fix clock leak and spurious timer in settimeout()
msc313e_wdt_settimeout() unconditionally calls msc313e_wdt_start() which introduces two severe bugs:
- If the watchdog is already active, calling start() again will increase the reference count of the clock again. However stop() is only called once, the reference count is unbalance.
- If the watchdog is stopped, calling settimeout() will start the hardware timer accidentally.
Factor out the register-writing logic into a helper function. Only call
it in settimeout() if the watchdog is running. Otherwise, simply update
wdev->timeout.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-97969
- https://git.kernel.org/stable/c/2152a13ee2a9af09a668ebd053a8dbf771dadb80
- https://git.kernel.org/stable/c/2abf99a57b0b71b2b97745981f4039370ab78044
- https://git.kernel.org/stable/c/3db30f315935c2fb0d95f46b7a593b5b4d3ec3d0
- https://git.kernel.org/stable/c/faf1eb2895c87a8c0fb920439dddc7e0d97c6a69
- https://git.kernel.org/stable/c/68665016c7b777b44e27b6b0c1e6524c28ebe40a
- https://git.kernel.org/stable/c/77ef2aa8b46876ca9935f32dd874c517ccf5d880
- https://git.kernel.org/stable/c/a1dd0817776ea2a870ba2347001af13ddd4cb321
- https://github.com/advisories/GHSA-c6r8-8m99-q662