PT-2023-1653 · Linux+5 · Linux Kernel+5

Published

2022-01-03

·

Updated

2024-03-27

·

CVE-2023-22995

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17
Description The issue is related to an error path in the dwc3 qcom acpi register core function in the Linux kernel, specifically in the drivers/usb/dwc3/dwc3-qcom.c file. This error path lacks certain platform device put and kfree calls. The vulnerability is also described as a buffer copy without checking the size of the input data, which can be exploited to cause a denial of service.
Recommendations For Linux kernel versions prior to 5.17, update to version 5.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the dwc3-qcom.c driver to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1647
ALT-PU-2022-1730
ALT-PU-2022-1768
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-25318
BDU:2023-01191
CVE-2023-22995
OESA-2023-1177
OESA-2023-1178
OPENSUSE-SU-2023_0774-1
SUSE-SU-2023:0749-1
SUSE-SU-2023:0749-2
SUSE-SU-2023:0774-1
SUSE-SU-2023:0778-1
SUSE-SU-2023:0779-1
SUSE-SU-2023:0780-1
SUSE-SU-2023:1608-1
SUSE-SU-2023:1609-1
SUSE-SU-2023:1710-1
USN-6681-1
USN-6681-2
USN-6681-3
USN-6681-4
USN-6686-1
USN-6686-2
USN-6686-3
USN-6686-4
USN-6686-5
USN-6705-1
USN-6716-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu