cbcvebase.
CVE-2023-52528
published 2024-03-02

CVE-2023-52528: In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg syzbot reported the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg syzbot reported the following uninit-value access issue: BUG: KMSAN: uninit-value in smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline] BUG: KMSAN: uninit-value in smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482 CPU: 0 PID: 8696 Comm: kworker/0:3 Not tainted 5.8.0-rc5-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Workqueue: usb_hub_wq hub_event Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0x21c/0x280 lib/dump_stack.c:118 kmsan_report+0xf7/0x1e0 mm/kmsan/kmsan_report.c:121 __msan_warning+0x58/0xa0 mm/kmsan/kmsan_instr.c:215 smsc75xx_wait_ready drivers/net/usb/smsc75xx.c:975 [inline] smsc75xx_bind+0x5c9/0x11e0 drivers/net/usb/smsc75xx.c:1482 usbnet_probe+0x1152/0x3f90 drivers/net/usb/usbnet.c:1737 usb_probe_interface+0xece/0x1550 drivers/usb/core/driver.c:374 really_probe+0xf20/0x20b0 drivers/base/dd.c:529 driver_probe_device+0x293/0x390 drivers/base/dd.c:701 __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807 bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431 __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873 device_initial_probe+0x4a/0x60 drivers/base/dd.c:920 bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491 device_add+0x3b0e/0x40d0 drivers/base/core.c:2680 usb_set_configuration+0x380f/0x3f10 drivers/usb/core/message.c:2032 usb_generic_driver_probe+0x138/0x300 drivers/usb/core/generic.c:241 usb_probe_device+0x311/0x490 drivers/usb/core/driver.c:272 really_probe+0xf20/0x20b0 drivers/base/dd.c:529 driver_probe_device+0x293/0x390 drivers/base/dd.c:701 __device_attach_driver+0x63f/0x830 drivers/base/dd.c:807 bus_for_each_drv+0x2ca/0x3f0 drivers/base/bus.c:431 __device_attach+0x4e2/0x7f0 drivers/base/dd.c:873 device_initial_probe+0x4a/0x60 drivers/base/dd.c:920 bus_probe_device+0x177/0x3d0 drivers/base/bus.c:491 device_add+0x3b0e/0x

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 3e0af6eec1789fd11934164a7f4dbcad979855a43e0af6eec1789fd11934164a7f4dbcad979855a4
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 2a36d9e2995c8c3c3f179aab1215a69cff06cbed2a36d9e2995c8c3c3f179aab1215a69cff06cbed
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 310f1c92f65ad905b7e81fe14de82d979ebbd825310f1c92f65ad905b7e81fe14de82d979ebbd825
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 30bc4d7aebe33904b0f2d3aad4b4a9c6029ad0c530bc4d7aebe33904b0f2d3aad4b4a9c6029ad0c5
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < cda10784a176d7192f08ecb518f777a4e9575812cda10784a176d7192f08ecb518f777a4e9575812
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 9ffc5018020fe646795a8dc1203224b8f776dc099ffc5018020fe646795a8dc1203224b8f776dc09
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 4931e80da9463b03bfe42be54a9a19f213b0f76d4931e80da9463b03bfe42be54a9a19f213b0f76d
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < e9c65989920f7c28775ec4e0c11b483910fb67b8e9c65989920f7c28775ec4e0c11b483910fb67b8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 6.5.8-16.5.8-1
linuxlinux_kernel>= 0 < 4.4.0-260.2944.4.0-260.294
linuxlinux_kernel>= 0 < 4.15.0-230.2424.15.0-230.242
linuxlinux_kernel>= 2.6.34 < 4.14.3274.14.327
linuxlinux_kernel>= 4.15 < 4.19.2964.19.296
linuxlinux_kernel>= 4.20 < 5.4.2585.4.258
linuxlinux_kernel>= 5.11 < 5.15.1355.15.135
linuxlinux_kernel>= 5.16 < 6.1.576.1.57
linuxlinux_kernel>= 5.5 < 5.10.1985.10.198
linuxlinux_kernel>= 6.2 < 6.5.76.5.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.