Resource management error in Linux kernel net usb driver



Published: 2024-06-27
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-52742
CWE-ID CWE-399
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource management error

EUVDB-ID: #VU93466

Risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52742

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the pl_vendor_req() function in drivers/net/usb/plusb.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions

External links

http://git.kernel.org/stable/c/f0ad46ef772438c0596df370450d8bdc8a12dbfb
http://git.kernel.org/stable/c/6f69307f625904feed189008381fd83bd1a35b63
http://git.kernel.org/stable/c/43379fcacea2dcee35d02efc9c8fe97807a503c9
http://git.kernel.org/stable/c/1be271c52bf3554edcb8d124d1f8c7f777ee5727
http://git.kernel.org/stable/c/25141fb4119112f4ebf8f00cf52014abbc8020b1
http://git.kernel.org/stable/c/0d2cf3fae701646061e295815bb7588d2f3671cc
http://git.kernel.org/stable/c/811d581194f7412eda97acc03d17fc77824b561f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###