PT-2023-1004 · Linux+5 · Linux Kernel+5
Pietro Borrello
·
Publicado
2023-01-31
·
Atualizado
2024-04-15
·
CVE-2023-25012
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 6.1.9
Description
The issue is related to a Use-After-Free in the
bigben remove function in drivers/hid/hid-bigbenff.c. This can be exploited via a crafted USB device, potentially leading to a denial of service or local escalation of privilege. The exploitation does not require additional execution privileges or user interaction. The vulnerability is caused by the LED controllers remaining registered for too long.Recommendations
For Linux kernel versions through 6.1.9, consider disabling the
bigben remove function in drivers/hid/hid-bigbenff.c as a temporary workaround to minimize the risk of exploitation. Restrict access to the hid-bigbenff driver to prevent the use of crafted USB devices.Exploit
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu