PT-2023-1653 · Linux+5 · Linux Kernel+5

Publicado

2022-01-03

·

Atualizado

2024-03-27

·

CVE-2023-22995

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17
Description The issue is related to an error path in the dwc3 qcom acpi register core function in the Linux kernel, specifically in the drivers/usb/dwc3/dwc3-qcom.c file. This error path lacks certain platform device put and kfree calls. The vulnerability is also described as a buffer copy without checking the size of the input data, which can be exploited to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.17, update to version 5.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the dwc3-qcom.c driver to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2022-1647
ALT-PU-2022-1730
ALT-PU-2022-1768
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-25318
BDU:2023-01191
CVE-2023-22995
OESA-2023-1177
OESA-2023-1178
OPENSUSE-SU-2023_0774-1
SUSE-SU-2023:0749-1
SUSE-SU-2023:0749-2
SUSE-SU-2023:0774-1
SUSE-SU-2023:0778-1
SUSE-SU-2023:0779-1
SUSE-SU-2023:0780-1
SUSE-SU-2023:1608-1
SUSE-SU-2023:1609-1
SUSE-SU-2023:1710-1
USN-6681-1
USN-6681-2
USN-6681-3
USN-6681-4
USN-6686-1
USN-6686-2
USN-6686-3
USN-6686-4
USN-6686-5
USN-6705-1
USN-6716-1

Produtos afetados

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu