CVE-2023-37453
Summary
| CVE | CVE-2023-37453 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-06 17:15:00 UTC |
| Updated | 2023-11-07 04:16:00 UTC |
| Description | An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Linux |
Linux Kernel |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [syzbot] [usb?] KASAN: slab-out-of-bounds Read in read_descriptors (3) |
|
lore.kernel.org |
|
| KASAN: slab-out-of-bounds Read in read_descriptors |
MISC |
lore.kernel.org |
|
| KASAN: slab-out-of-bounds Read in read_descriptors |
|
lore.kernel.org |
|
| [syzbot] [usb?] KASAN: slab-out-of-bounds Read in read_descriptors (3) |
MISC |
lore.kernel.org |
|
| KASAN: slab-out-of-bounds Read in read_descriptors (3) |
MISC |
syzkaller.appspot.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199803 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6415-1)
- 199976 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-1)
- 199996 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-1)
- 199997 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-1)
- 199999 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6548-2)
- 200002 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-2)
- 200003 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-6549-2)
- 200006 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-6548-3)
- 200007 Ubuntu Security Notification for Linux kernel (Low Latency) Vulnerabilities (USN-6549-3)
- 200010 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6534-3)
- 200024 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6549-4)
- 200035 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6549-5)
- 200037 Ubuntu Security Notification for Linux kernel (IoT) Vulnerabilities (USN-6548-5)
- 200113 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6635-1)
- 673595 EulerOS Security Update for kernel (EulerOS-SA-2023-3247)
- 673692 EulerOS Security Update for kernel (EulerOS-SA-2023-3275)
- 754832 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3600-1)
- 754833 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3599-1)
- 754855 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3656-1)
- 754867 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3683-1)
- 754868 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3682-1)
- 754884 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3704-1)
- 754899 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3599-2)
- 754900 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3600-2)
- 754901 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3704-2)
- 754903 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3683-2)
- 755026 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3964-1)
- 755037 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3971-1)
- 755038 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3969-1)
- 755043 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:3988-1)
- 755082 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4058-1)
- 755083 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:4057-1)
- 907562 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (27388-1)