PT-2024-14700 · Linux+7 · Linux Kernel+7
Syzbot
·
Published
2023-02-13
·
Updated
2025-09-29
·
CVE-2023-52703
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the Linux kernel, specifically in the net/usb: kalmia module. The problem arises when
act len in kalmia send init packet() is uninitialized and passed to the first usb bulk msg error path. It has been noted that passing act len in the error path is pointless, and the value printed in the second error path would be from the first call to usb bulk msg. To resolve this, it is recommended to not pass act len to the usb bulk msg error paths.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Access of Uninitialized Pointer
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse