CVE-2023-52855
Last modified
CVE-2023-52855 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency In _dwc2_hcd_urb_enqueue(), "urb->hcpriv = NULL" is executed without holding the lock "hsotg->lock". In _dwc2_hcd_urb_dequeue(): spin_lock_irqsave(&hsotg->lock, flags); ... if (!urb->hcpriv) { dev_dbg(hsotg->dev, "## urb->hcpriv is NULL ##\n"); goto out; } rc = dwc2_hcd_urb_dequeue(hsotg, urb->hcpriv); // Use urb->hcpriv ... out: spin_unlock_irqrestore(&hsotg->lock, flags); When _dwc2_hcd_urb_enqueue() and _dwc2_hcd_urb_dequeue() are concurrently executed, the NULL check of "urb->hcpriv" can be executed before "urb->hcpriv = NULL". EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency In _dwc2_hcd_urb_enqueue(), "urb->hcpriv = NULL" is executed without holding the lock "hsotg->lock". In _dwc2_hcd_urb_dequeue(): spin_lock_irqsave(&hsotg->lock, flags); ... if (!urb->hcpriv) { dev_dbg(hsotg->dev, "## urb->hcpriv is NULL ##\n"); goto out; } rc = dwc2_hcd_urb_dequeue(hsotg, urb->hcpriv); // Use urb->hcpriv ... out: spin_unlock_irqrestore(&hsotg->lock, flags); When _dwc2_hcd_urb_enqueue() and _dwc2_hcd_urb_dequeue() are concurrently executed, the NULL check of "urb->hcpriv" can be executed before "urb->hcpriv = NULL". After urb->hcpriv is NULL, it can be used in the function call to dwc2_hcd_urb_dequeue(), which can cause a NULL pointer dereference. This possible bug is found by an experimental static analysis tool developed by myself. This tool analyzes the locking APIs to extract function pairs that can be concurrently executed, and then analyzes the instructions in the paired functions to identify possible concurrency bugs including data races and atomicity violations. The above possible bug is reported, when my tool analyzes the source code of Linux 6.5. To fix this possible bug, "urb->hcpriv = NULL" should be executed with holding the lock "hsotg->lock". After using this patch, my tool never reports the possible bug, with the kernelconfiguration allyesconfig for x86_64. Because I have no associated hardware, I cannot test the patch in runtime testing, and just verify it according to the code logic.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.2, < 4.14.330 |
| Linux | Linux Kernel | >= 4.15, < 4.19.299 |
| Linux | Linux Kernel | >= 4.20, < 5.4.261 |
| Linux | Linux Kernel | >= 5.5, < 5.10.201 |
| Linux | Linux Kernel | >= 5.11, < 5.15.139 |
| Linux | Linux Kernel | >= 5.16, < 6.1.63 |
| Linux | Linux Kernel | >= 6.2, < 6.5.12 |
| Linux | Linux Kernel | >= 6.6, < 6.6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-52855?
How severe is CVE-2023-52855?
How do I fix CVE-2023-52855?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5285A vulnerability classified as critical was found in Tongda O…7.5
- CVE-2023-52850In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-52851In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-52852In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-52853In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-52854In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-52856In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-52857In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2023-52858In the Linux kernel, the following vulnerability has been re…6.2
- CVE-2023-52859In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-5286A vulnerability, which was classified as problematic, has be…5.4
- CVE-2023-52860In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2023-52855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
