PT-2023-9750 · Linux+3 · Linux Kernel+3

Publicado

2023-09-22

·

Atualizado

2025-02-03

·

CVE-2023-52754

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the imon driver in the Linux kernel, which probes two USB interfaces. At the probe of the second interface, the driver assumes the first interface is bound with the same imon driver, which may not always be true, especially if the first interface is bound with another driver via a malformed descriptor. This can lead to memory corruption, as the imon driver accesses data from drvdata as a struct imon context object, which may be a completely different one assigned by another driver. A patch adds a sanity check to avoid this problem by verifying whether the first interface is really bound with the imon driver.
Recommendations To resolve the issue, apply the patch that adds a sanity check to verify whether the first interface is bound with the imon driver. This patch is described as "media: imon: fix access to invalid resource for the second interface" and is intended to prevent memory corruption by ensuring the imon driver only accesses data from the correct interface.

Exploit

Correção

Memory Leak

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-10417
CVE-2023-52754
OESA-2024-1705
OESA-2024-2126
OESA-2024-2324
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Produtos afetados

Astra Linux
Linux Kernel
Red Os
Suse