CVE-2023-1073
Published: October 18, 2023Last modified: October 18, 2023
Description
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.6 |
Attack Vector | PHYSICAL |
Attack complexity | LOW |
Privileges required | LOW |
User interaction | NONE |
Scope | UNCHANGED |
Confidentiality | HIGH |
Integrity impact | HIGH |
Availability impact | HIGH |
Vector | CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | Stream | linux-lts | Unknown (6.1.33-r0) |
References
- http://www.openwall.com/lists/oss-security/2023/11/05/2
- http://www.openwall.com/lists/oss-security/2023/11/05/3
- https://bugzilla.redhat.com/show_bug.cgi?id=2173403
- https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/id=b12fece4c64857e5fab4290bf01b2e0317a88456
- https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
- https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
- https://www.openwall.com/lists/osssecurity/2023/01/17/3