PT-2023-1653 · Linux+5 · Linux Kernel+5
Publicado
2022-01-03
·
Atualizado
2024-03-27
·
CVE-2023-22995
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17
Description
The issue is related to an error path in the dwc3 qcom acpi register core function in the Linux kernel, specifically in the drivers/usb/dwc3/dwc3-qcom.c file. This error path lacks certain platform device put and kfree calls. The vulnerability is also described as a buffer copy without checking the size of the input data, which can be exploited to cause a denial of service.
Recommendations
For Linux kernel versions prior to 5.17, update to version 5.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the dwc3-qcom.c driver to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu