cbcvebase.
CVE-2023-52781
published 2024-05-21

CVE-2023-52781: In the Linux kernel, the following vulnerability has been resolved: usb: config: fix iteration issue in 'usb_get_bos_descriptor()' The BOS descriptor defines a…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: config: fix iteration issue in 'usb_get_bos_descriptor()' The BOS descriptor defines a root descriptor and is the base descriptor for accessing a family of related descriptors. Function 'usb_get_bos_descriptor()' encounters an iteration issue when skipping the 'USB_DT_DEVICE_CAPABILITY' descriptor type. This results in the same descriptor being read repeatedly. To address this issue, a 'goto' statement is introduced to ensure that the pointer and the amount read is updated correctly. This ensures that the function iterates to the next descriptor instead of reading the same descriptor repeatedly.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.66-1 (bookworm)linux 6.1.66-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.79 < 3.173.17
linuxlinux>= 3dd550a2d36596a1b0ee7955da3b611c031d3873 < 9ef94ec8e52eaf7b9abc5b5f8f5b9117511122239ef94ec8e52eaf7b9abc5b5f8f5b911751112223
linuxlinux>= 3dd550a2d36596a1b0ee7955da3b611c031d3873 < 64c27b7b2357ddb38b6afebaf46d5bff4d25070264c27b7b2357ddb38b6afebaf46d5bff4d250702
linuxlinux>= 3dd550a2d36596a1b0ee7955da3b611c031d3873 < f89fef7710b2ba0f7a1e46594e530dcf2f77be91f89fef7710b2ba0f7a1e46594e530dcf2f77be91
linuxlinux>= 3dd550a2d36596a1b0ee7955da3b611c031d3873 < 7c0244cc311a4038505b73682b7c8ceaa5c7a8c87c0244cc311a4038505b73682b7c8ceaa5c7a8c8
linuxlinux>= 3dd550a2d36596a1b0ee7955da3b611c031d3873 < 974bba5c118f4c2baf00de0356e3e4f7928b4cbc974bba5c118f4c2baf00de0356e3e4f7928b4cbc
linuxlinux>= 4.14.146 < 4.154.15
linuxlinux>= 4.19.75 < 4.204.20
linuxlinux>= 4.4.194 < 4.54.5
linuxlinux>= 4.9.194 < 4.104.10
linuxlinux>= 5.2.17 < 5.35.3
linuxlinux>= 5.3.1 < 5.45.4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.205-15.10.205-1
linuxlinux_kernel>= 0 < 6.1.66-16.1.66-1
linuxlinux_kernel>= 0 < 6.6.8-16.6.8-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.