#VU93466 Resource management error in Linux kernel


Published: 2024-06-27

Vulnerability identifier: #VU93466

Vulnerability risk: Low

CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2023-52742

CWE-ID: CWE-399

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the pl_vendor_req() function in drivers/net/usb/plusb.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/f0ad46ef772438c0596df370450d8bdc8a12dbfb
http://git.kernel.org/stable/c/6f69307f625904feed189008381fd83bd1a35b63
http://git.kernel.org/stable/c/43379fcacea2dcee35d02efc9c8fe97807a503c9
http://git.kernel.org/stable/c/1be271c52bf3554edcb8d124d1f8c7f777ee5727
http://git.kernel.org/stable/c/25141fb4119112f4ebf8f00cf52014abbc8020b1
http://git.kernel.org/stable/c/0d2cf3fae701646061e295815bb7588d2f3671cc
http://git.kernel.org/stable/c/811d581194f7412eda97acc03d17fc77824b561f


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability