Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: config: fix iteration issue in 'usb_get_bos_descriptor()' The BOS descriptor defines a root descriptor and is the base descriptor for accessing a family of related descriptors. Function 'usb_get_bos_descriptor()' encounters an iteration issue when skipping the 'USB_DT_DEVICE_CAPABILITY' descriptor type. This results in the same descriptor being read repeatedly. To address this issue, a 'goto' statement is introduced to ensure that the pointer and the amount read is updated correctly. This ensures that the function iterates to the next descriptor instead of reading the same descriptor repeatedly.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.16.79, < 3.17 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/64c27b7b2357ddb38b6afebaf46d5bff4d250702Patch
- https://git.kernel.org/stable/c/7c0244cc311a4038505b73682b7c8ceaa5c7a8c8Patch
- https://git.kernel.org/stable/c/974bba5c118f4c2baf00de0356e3e4f7928b4cbcPatch
- https://git.kernel.org/stable/c/9ef94ec8e52eaf7b9abc5b5f8f5b911751112223Patch
- https://git.kernel.org/stable/c/f89fef7710b2ba0f7a1e46594e530dcf2f77be91Patch
- https://git.kernel.org/stable/c/64c27b7b2357ddb38b6afebaf46d5bff4d250702Patch
- https://git.kernel.org/stable/c/7c0244cc311a4038505b73682b7c8ceaa5c7a8c8Patch
- https://git.kernel.org/stable/c/974bba5c118f4c2baf00de0356e3e4f7928b4cbcPatch
- https://git.kernel.org/stable/c/9ef94ec8e52eaf7b9abc5b5f8f5b911751112223Patch
- https://git.kernel.org/stable/c/f89fef7710b2ba0f7a1e46594e530dcf2f77be91Patch
FAQ
What is CVE-2023-52781?
CVE-2023-52781 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: usb: config: fix iteration issue in 'usb_get_bos_descriptor()' The BOS descriptor defines a root descriptor and is the base descri...
How severe is CVE-2023-52781?
CVE-2023-52781 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52781?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.