#VU72741 Use-after-free in Linux kernel - CVE-2023-1079
Published: March 3, 2023
Linux kernel
Linux Foundation
Description
The vulnerability allows an attacker to compromise the vulnerable system.
The vulnerability exists due to a use-after-free error within the asus_kbd_backlight_set() function when plugging in a malicious USB device. An attacker with physical access to the system can inject a malicious USB device, trigger a use-after-free error and execute arbitrary code.