PT-2023-9748 · Linux+2 · Linux Kernel+2

Jinjie Ruan

·

Publicado

2023-10-25

·

Atualizado

2025-02-03

·

CVE-2023-52866

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.0-rc2+
Description The vulnerability is related to a user-memory-access bug in the uclogic params ugee v2 init event hooks() function. When CONFIG HID UCLOGIC=y and CONFIG KUNIT ALL TESTS=y, the bug occurs, causing a general protection fault. The issue arises when hid test uclogic params cleanup event hooks() calls uclogic params ugee v2 init event hooks() with a null argument, leading to a null pointer dereference in uclogic params ugee v2 has battery(). The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the uclogic params ugee v2 init event hooks() function. Specifically, update to a version later than 6.6.0-rc2+.
As a temporary workaround, consider disabling the uclogic params ugee v2 init event hooks() function until a patch is available. However, this may have unintended consequences and should be approached with caution.
Note: The provided information does not specify the exact version that includes the fix, so it is recommended to update to the latest available version of the Linux kernel.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-10415
CVE-2023-52866
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Produtos afetados

Linux Kernel
Red Os
Suse