PT-2022-6413 · Linux+1 · Linux Kernel+1
Published
2022-01-06
·
Updated
2025-03-20
·
CVE-2023-22999
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.16.3
Description
The issue is related to the misinterpretation of the
dwc3 qcom create urs usb platdev return value in the drivers/usb/dwc3/dwc3-qcom.c file of the Linux kernel. This misinterpretation can lead to a denial of service. The dwc3 qcom probe() function is specifically affected by this issue due to incorrect error pointer checking.Recommendations
For Linux kernel versions prior to 5.16.3, update to version 5.16.3 or later to resolve the issue. As a temporary workaround, consider disabling the
dwc3 qcom probe() function until a patch is available. Restrict access to the vulnerable dwc3-qcom.c module to minimize the risk of exploitation. Avoid using the dwc3 qcom create urs usb platdev function in the affected kernel version until the issue is resolved.Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linux Kernel