Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-25012
HistoryFeb 02, 2023 - 12:00 a.m.

CVE-2023-25012

2023-02-0200:00:00
ubuntu.com
ubuntu.com
11
linux kernel
use-after-free
hid-bigbenff
usb device
led controllers

4.6 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

34.4%

The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in
drivers/hid/hid-bigbenff.c via a crafted USB device because the LED
controllers remain registered for too long.

Notes

Author Note
sbeattie requires the removal of the device to exploit, usually implying physical access. upstream submission claims the issue was introduced in 4eb1b01de5b9 (“HID: hid-bigbenff: fix race condition for scheduled work during removal”), which may also have a security impact.
Rows per page:
1-10 of 611

4.6 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

34.4%