CVE-2022-23467
Summary
| CVE | CVE-2022-23467 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-05 20:15:00 UTC |
| Updated | 2022-12-06 20:34:00 UTC |
| Description | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. Using a modified USB device an attacker can leak stack addresses of the `razer_attr_read_dpi_stages`, potentially bypassing KASLR. To exploit this vulnerability an attacker would need to access to a users keyboard or mouse or would need to convince a user to use a modified device. The issue has been patched in v3.5.1. Users are advised to upgrade and should be reminded not to plug in unknown USB devices. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Out of Bounds Read in OpenRazer Driver · Advisory · openrazer/openrazer · GitHub |
MISC |
github.com |
|
| driver: Sanitize data_size value returned from devices · openrazer/openrazer@33aa7f0 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183938 Debian Security Update for openrazer (CVE-2022-23467)
- 503208 Alpine Linux Security Update for openrazer
- 506144 Alpine Linux Security Update for openrazer