#VU80795 Out-of-bounds read in Linux kernel - CVE-2023-37453
Published: September 14, 2023
Linux kernel
Linux Foundation
Description
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the read_descriptors() function in drivers/usb/core/sysfs.c. An attacker with physical access to the system can attach a malicious USB device, trigger an out-of-bounds read error and crash the kernel.