cbcvebase.
CVE-2023-52655
published 2024-05-14

CVE-2023-52655: In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet that is…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.5th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet that is inbetween 0 and sizeof(u64) the value passed to skb_trim() as length will wrap around ending up as some very large value. The driver will then proceed to parse the header located at that position, which will either oops or process some random value. The fix is to check against sizeof(u64) rather than 0, which the driver currently does. The issue exists since the introduction of the driver.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.69-1 (bookworm)linux 6.1.69-1 (bookworm)
linuxlinux
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < 84f2e5b3e70f08fce3cb1ff73414631c5e49020484f2e5b3e70f08fce3cb1ff73414631c5e490204
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < d69581c17608d81824dd497d9a54b6a5b6139975d69581c17608d81824dd497d9a54b6a5b6139975
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < 46412b2fb1f9cc895d6d4036bf24f640b5d86dab46412b2fb1f9cc895d6d4036bf24f640b5d86dab
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < 82c386d73689a45d5ee8c1290827bce64056dddd82c386d73689a45d5ee8c1290827bce64056dddd
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < 2ebf775f0541ae0d474836fa0cf3220e502f8e3e2ebf775f0541ae0d474836fa0cf3220e502f8e3e
linuxlinux>= 361459cd9642631f048719169da9ef14cbf4a932 < ccab434e674ca95d483788b1895a70c21b7f016accab434e674ca95d483788b1895a70c21b7f016a
linuxlinux_kernel< 5.4.2655.4.265
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.69-16.1.69-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1
linuxlinux_kernel>= 5.11 < 5.15.1445.15.144
linuxlinux_kernel>= 5.16 < 6.1.696.1.69
linuxlinux_kernel>= 5.5 < 5.10.2055.10.205
linuxlinux_kernel>= 6.2 < 6.6.86.6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.