PT-2025-41088 · Linux+1 · Linux Kernel+1
Published
2023-04-20
·
Updated
2025-12-04
·
CVE-2023-53644
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.1.0-rc4-syzkaller
Description
The Linux kernel radio-shark2 driver did not validate the presence and type of endpoints it utilized. This could lead to a WARNING message during operation, as identified by the syzbot fuzzer. The issue stems from a lack of checks to ensure endpoints are present and of the correct type. The
usb submit urb function was implicated in the observed behavior, triggered during a shark write reg operation. The usb start wait urb and usb bulk msg functions were also part of the call trace.Recommendations
Update to a version of the Linux kernel that includes the fix for this issue.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Suse