PT-2023-1653 · Linux+5 · Linux Kernel+5
Published
2022-01-03
·
Updated
2024-03-27
·
CVE-2023-22995
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.17
Description
The issue is related to an error path in the dwc3 qcom acpi register core function in the Linux kernel, specifically in the drivers/usb/dwc3/dwc3-qcom.c file. This error path lacks certain platform device put and kfree calls. The vulnerability is also described as a buffer copy without checking the size of the input data, which can be exploited to cause a denial of service.
Recommendations
For Linux kernel versions prior to 5.17, update to version 5.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the dwc3-qcom.c driver to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu