PT-2023-9748 · Linux+2 · Linux Kernel+2

Jinjie Ruan

·

Published

2023-10-25

·

Updated

2025-02-03

·

CVE-2023-52866

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.0-rc2+
Description The vulnerability is related to a user-memory-access bug in the uclogic params ugee v2 init event hooks() function. When CONFIG HID UCLOGIC=y and CONFIG KUNIT ALL TESTS=y, the bug occurs, causing a general protection fault. The issue arises when hid test uclogic params cleanup event hooks() calls uclogic params ugee v2 init event hooks() with a null argument, leading to a null pointer dereference in uclogic params ugee v2 has battery(). The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the uclogic params ugee v2 init event hooks() function. Specifically, update to a version later than 6.6.0-rc2+.
As a temporary workaround, consider disabling the uclogic params ugee v2 init event hooks() function until a patch is available. However, this may have unintended consequences and should be approached with caution.
Note: The provided information does not specify the exact version that includes the fix, so it is recommended to update to the latest available version of the Linux kernel.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10415
CVE-2023-52866
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Affected Products

Linux Kernel
Red Os
Suse