Description
A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device, which advertises itself as an Asus device. Similarly to the previous known CVE-2023-25012, but in asus devices, the work_struct may be scheduled by the LED controller while the device is disconnecting, triggering a use-after-free on the struct asus_kbd_leds *led structure. A malicious USB device may exploit the issue to cause memory corruption with controlled data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3403-1 | linux security update |
Debian DLA |
DLA-3404-1 | linux-5.10 security update |
EUVD |
EUVD-2023-23367 | A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device, which advertises itself as an Asus device. Similarly to the previous known CVE-2023-25012, but in asus devices, the work_struct may be scheduled by the LED controller while the device is disconnecting, triggering a use-after-free on the struct asus_kbd_leds *led structure. A malicious USB device may exploit the issue to cause memory corruption with controlled data. |
Ubuntu USN |
USN-6033-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-6171-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6172-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6185-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6187-1 | Linux kernel (IBM) vulnerabilities |
Ubuntu USN |
USN-6207-1 | Linux kernel (Intel IoTG) vulnerabilities |
Ubuntu USN |
USN-6222-1 | Linux kernel (Xilinx ZynqMP) vulnerabilities |
Ubuntu USN |
USN-6223-1 | Linux kernel (Azure CVM) vulnerabilities |
Ubuntu USN |
USN-6256-1 | Linux kernel (IoT) vulnerabilities |
Ubuntu USN |
USN-6604-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-6604-2 | Linux kernel (Azure) vulnerabilities |
References
History
Wed, 19 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-19T21:36:25.856Z
Reserved: 2023-02-27T00:00:00.000Z
Link: CVE-2023-1079
Updated: 2024-08-02T05:32:46.383Z
Status : Modified
Published: 2023-03-27T21:15:10.573
Modified: 2025-02-19T22:15:11.597
Link: CVE-2023-1079
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN