PT-2023-9748 · Linux+2 · Linux Kernel+2
Jinjie Ruan
·
Published
2023-10-25
·
Updated
2025-02-03
·
CVE-2023-52866
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.0-rc2+
Description
The vulnerability is related to a user-memory-access bug in the
uclogic params ugee v2 init event hooks() function. When CONFIG HID UCLOGIC=y and CONFIG KUNIT ALL TESTS=y, the bug occurs, causing a general protection fault. The issue arises when hid test uclogic params cleanup event hooks() calls uclogic params ugee v2 init event hooks() with a null argument, leading to a null pointer dereference in uclogic params ugee v2 has battery(). The vulnerability can be exploited to cause a denial of service.Recommendations
To resolve the issue, update the Linux kernel to a version that includes the fix for the
uclogic params ugee v2 init event hooks() function. Specifically, update to a version later than 6.6.0-rc2+.As a temporary workaround, consider disabling the
uclogic params ugee v2 init event hooks() function until a patch is available. However, this may have unintended consequences and should be approached with caution.Note: The provided information does not specify the exact version that includes the fix, so it is recommended to update to the latest available version of the Linux kernel.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Os
Suse