CVE-2023-1073 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel
Severity
6.6MEDIUMNVD
OSV8.8OSV5.5OSV4.7OSV4.6
EPSS
0.0%
top 94.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateFeb 13
Description
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9
Affected Packages3 packages
Also affects: Enterprise Linux 7.0, 8.0, 9.0, Fedora 37
Patches
🔴Vulnerability Details
19GHSA▶
GHSA-3chx-g7jg-4263: A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device↗2023-07-06